Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34,806 advisories

Loading
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check High
GHSA-mf7q-r4rv-jv94 was published for github.com/crossplane/crossplane-runtime/v2 (Go) Aug 27, 2026
tonghuaroot Credited to tonghuaroot and bugbunny-research bugbunny-research bugbunny-research
libreoffice-convert vulnerable to path traversal / arbitrary file write Moderate
CVE-2026-54732 was published for libreoffice-convert (npm) Aug 27, 2026
Santoshkumarpuppala Credited to Santoshkumarpuppala
silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template High
CVE-2026-54718 was published for symbiote/silverstripe-advancedworkflow (Composer) Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter Low
CVE-2026-42350 was published for github.com/akuity/kargo (Go) Aug 27, 2026
PontusHanssen Credited to PontusHanssen, krancour, and rpelczar krancour krancour
rpelczar rpelczar
n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter) Moderate
CVE-2026-54687 was published for n8n-nodes-sqlite3 (npm) Aug 27, 2026
dyingman1 Credited to dyingman1
cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions Low
CVE-2026-54713 was published for cakephp/queue (Composer) Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject High
CVE-2026-54721 was published for silverstripe/userforms (Composer) Aug 27, 2026
Silverstripe Framework: Possible XSS attack through media embed Moderate
CVE-2026-54720 was published for silverstripe/framework (Composer) Aug 27, 2026
OpenSTAManager has HTML Injection in modules/utenti/edit.php Low
CVE-2026-44701 was published for devcode-it/openstamanager (Composer) Aug 26, 2026
ilmercu Credited to ilmercu
LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates High
GHSA-7w8c-qgxg-m7jx was published for librenms/librenms (Composer) Aug 26, 2026
TristanInSec Credited to TristanInSec
asyncssh has SCP Path Traversal to Arbitrary File Write High
CVE-2026-54591 was published for asyncssh (pip) Aug 26, 2026
Jaden-Furtado Credited to Jaden-Furtado and JadenFurtado JadenFurtado JadenFurtado
cakephp/debug_kit: MailPreview contains unsafe reflection Moderate
CVE-2026-54614 was published for cakephp/debug_kit (Composer) Aug 26, 2026
edorian Credited to edorian
senaite.core Vulnerable to Eval Injection and Missing Authorization Critical
CVE-2026-54569 was published for senaite.core (pip) Aug 26, 2026
snomi Credited to snomi and Volcore Volcore Volcore
SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed High
CVE-2026-54606 was published for suneditor (npm) Aug 26, 2026
Adyej999 Credited to Adyej999
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root High
CVE-2026-54563 was published for github.com/cloudreve/Cloudreve/v3 (Go) Aug 26, 2026
riodrwn Credited to riodrwn
dizconnectz Credited to dizconnectz and nemesifier nemesifier nemesifier
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise) Critical
GHSA-93qj-5q5v-3c2h was published for pantheon-agents (pip) Aug 26, 2026
AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore Moderate
CVE-2026-55688 was published for org.asynchttpclient:async-http-client (Maven) Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation Low
CVE-2026-54786 was published for wasmtime-wasi (Rust) Aug 26, 2026
alexcrichton Credited to alexcrichton
@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys High
CVE-2026-54511 was published for @logtape/syslog (npm) Aug 26, 2026
IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries High
CVE-2026-54550 was published for org.codehaus.izpack:izpack-installer (Maven) Aug 26, 2026
sectroyer Credited to sectroyer
kas Persistently Disables SSH Host Key Checking Low
CVE-2026-54548 was published for kas (pip) Aug 26, 2026
shubtheone Credited to shubtheone
muslimbek-0x Credited to muslimbek-0x
ProTip! Advisories are also available from the GraphQL API