GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
165,159 advisories
Filter by severity
ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line...
Moderate
Unreviewed
CVE-2026-66011
was published
Jul 25, 2026
The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory...
Moderate
Unreviewed
CVE-2026-14955
was published
Jul 25, 2026
The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-15425
was published
Jul 25, 2026
A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing...
Moderate
Unreviewed
CVE-2026-66338
was published
Jul 25, 2026
A flaw was found in libsoup. An unsigned integer underflow in the...
Moderate
Unreviewed
CVE-2026-66337
was published
Jul 25, 2026
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup...
Moderate
Unreviewed
CVE-2026-66339
was published
Jul 25, 2026
The web management interface in
Tycon Systems TPDIN-Monitor-WEB2
stores and displays system...
Moderate
Unreviewed
CVE-2026-55985
was published
Jul 25, 2026
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
Moderate
GHSA-8q49-2h5h-434x
was published
for
@frontmcp/adapters
(npm)
Jul 24, 2026
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
Moderate
GHSA-jpcw-4wr7-c3vq
was published
for
github.com/getkin/kin-openapi
(Go)
Jul 24, 2026
Quasar: Prototype pollution in the extend() utility
Moderate
GHSA-3r53-75j5-3g7j
was published
for
quasar
(npm)
Jul 24, 2026
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
Moderate
GHSA-fwjx-9p69-h25h
was published
for
github.com/jandedobbeleer/oh-my-posh
(Go)
Jul 24, 2026
Shescape: Home-directory disclosure in assignment context on Unix with Dash
Moderate
GHSA-q53c-4prm-w95q
was published
for
shescape
(npm)
Jul 24, 2026
Shescape: Path disclosure on Unix with Zsh
Moderate
GHSA-6v4m-fw66-8r4x
was published
for
shescape
(npm)
Jul 24, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
Moderate
GHSA-86cx-wwf4-phq4
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
Moderate
GHSA-p6ph-3jx2-3337
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
swift-nio-http2: Missing CR/LF/NUL validation in header values
Moderate
CVE-2026-64785
was published
for
swift-nio-http2
(Swift)
Jul 24, 2026
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Moderate
GHSA-v6w6-358x-2433
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
Moderate
GHSA-qqc3-94qv-7fw3
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
Moderate
GHSA-f45q-w629-wr25
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
Moderate
GHSA-c534-2w9c-x7fm
was published
for
github.com/zxh326/kite
(Go)
Jul 24, 2026
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
Moderate
GHSA-hfhx-w8p8-4hc7
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Account Enumeration via Login Lockout Response Differential
Moderate
GHSA-cr7p-cr3q-h5cm
was published
for
@budibase/server
(npm)
Jul 24, 2026
Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin...
Moderate
Unreviewed
CVE-2026-57531
was published
Jul 24, 2026
Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown...
Moderate
Unreviewed
CVE-2026-57530
was published
Jul 24, 2026
Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
Moderate
GHSA-gh4h-34gr-87r7
was published
for
@budibase/server
(npm)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API