CVEs and GitHub security advisories

CVETargetVulnerability
CVE-2026-66066Ruby on Rails Active Storage >= 7.2.3.2 / 8.0.5.1 / 8.1.3.1Arbitrary File Read / RCE
CVE-2026-63219GeoNetwork >= 4.2.17 / 4.4.12Unauthenticated File Upload
CVE-2026-58400GeoNetwork >= 4.2.17 / 4.4.12Unsafe XSLT Execution
CVE-2026-57582GeoNetwork >= 4.2.17 / 4.4.12Reflected XSS
CVE-2026-56730Zammad >= 7.0.1Missing Authorization
CVE-2026-56728Zammad >= 7.0.1Broken Access Control
CVE-2026-55864GeoNetwork >= 4.2.17 / 4.4.12Server-Side Request Forgery
CVE-2023-33970Kanboard Management Software >= 1.2.29Broken Access Control
CVE-2023-33969Kanboard Management Software >= 1.2.29Stored XSS
CVE-2023-33968Kanboard Management Software >= 1.2.29Broken Access Control
CVE-2022-23912Wordpress AP Custom Testimonial Plugin >= 1.4.7Reflected XSS
CVE-2022-23911Wordpress AP Custom Testimonial Plugin >= 1.4.7SQL Injection
CVE-2022-0478Wordpress WooCommerce Event Manager Plugin >= 3.5.7SQL Injection
List of 0days I found through out time
GitHub AdvisoryTargetVulnerability
GHSA-vp58-j275-797xBetter-auth >= 1.1.20Open Redirect
GHSA-rq86-9m6r-cm3gSurrealDB >= 2.2.1Denial of Service