GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
28 advisories
Filter by severity
Snipe-IT has CSV formula injection in Activity Report export
Moderate
CVE-2026-55452
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none
Moderate
CVE-2026-55834
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Aug 28, 2026
mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)
Moderate
CVE-2026-55663
was published
for
mediasoup
(npm)
Aug 25, 2026
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
High
CVE-2026-55532
was published
for
PraisonAI
(pip)
Aug 25, 2026
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
Moderate
CVE-2026-55531
was published
for
PraisonAI
(pip)
Aug 25, 2026
Sakai Profile Image Deletion has an IDOR
Moderate
CVE-2026-54050
was published
for
org.sakaiproject.profile2:profile2-api
(Maven)
Aug 24, 2026
Sakai Conversations has a Stored XSS Issue
High
CVE-2026-54049
was published
for
org.sakaiproject.conversations:sakai-conversations-impl
(Maven)
Aug 24, 2026
SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
Moderate
CVE-2026-54688
was published
for
mcp-searxng
(npm)
Aug 19, 2026
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
High
CVE-2026-71307
was published
for
lemur
(pip)
Aug 18, 2026
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
High
CVE-2026-71303
was published
for
lemur
(pip)
Aug 18, 2026
MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
High
CVE-2026-69148
was published
for
mlflow
(npm)
Aug 17, 2026
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
Moderate
CVE-2026-69146
was published
for
mlflow
(npm)
Aug 17, 2026
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
Moderate
CVE-2026-68517
was published
for
glances
(pip)
Aug 17, 2026
Open WebUI: DNS Rebinding SSRF Bypass
Moderate
CVE-2026-54020
was published
for
open-webui
(pip)
Aug 4, 2026
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page
Moderate
CVE-2026-62280
was published
for
org.openidentityplatform.openam:openam-oauth2
(Maven)
Jul 24, 2026
TensorZero Gateway: Arbitrary file read and SSRF in internal object storage endpoint
High
CVE-2026-54457
was published
for
tensorzero
(pip)
Jul 15, 2026
SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon
Moderate
CVE-2026-54068
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jul 10, 2026
OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
High
CVE-2026-54641
was published
for
io.openremote:openremote-manager
(Maven)
Jul 6, 2026
Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources
Moderate
CVE-2026-49288
was published
for
statamic/cms
(Composer)
Jun 26, 2026
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
Moderate
GHSA-h4h3-3rfj-x6fq
was published
for
surrealdb
(Rust)
Jun 19, 2026
EverOS: Path traversal in EverOS /api/v1/memory/add via unvalidated sender_id
High
GHSA-c795-2g9c-j48m
was published
for
everos
(pip)
Jun 19, 2026
Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check
High
CVE-2026-53755
was published
for
crawl4ai
(pip)
Jun 16, 2026
Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution
High
GHSA-f989-c77f-r2cq
was published
for
crawl4ai
(pip)
Jun 16, 2026
NocoDB: SQL Injection via Column Title in Bulk GroupBy
Moderate
CVE-2026-47384
was published
for
nocodb
(npm)
Jun 5, 2026
Stored XSS in REDAXO
Moderate
CVE-2024-13209
was published
for
redaxo/source
(Composer)
Feb 10, 2025
ProTip!
Advisories are also available from the
GraphQL API