GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
15,587 advisories
Filter by severity
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability...
Low
Unreviewed
CVE-2026-16334
was published
Jul 21, 2026
@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
Low
GHSA-hp3v-mfqw-h74c
was published
for
@astrojs/netlify
(npm)
Jul 20, 2026
body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
Low
CVE-2026-12590
was published
for
body-parser
(npm)
Jul 20, 2026
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
Low
CVE-2026-59730
was published
for
@astrojs/node
(npm)
Jul 20, 2026
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
Low
CVE-2026-59727
was published
for
astro
(npm)
Jul 20, 2026
File Browser: Share API exposes the password hash and bypass token
Low
CVE-2026-62684
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
Forwarding of confidentials headers to third parties in fluture-node
Low
CVE-2022-24719
was published
for
fluture-node
(npm)
Mar 1, 2022
defuddle vulnerable to XSS via unescaped string interpolation in _findContentBySchemaText image tag
Low
CVE-2026-30830
was published
for
defuddle
(npm)
Mar 6, 2026
NocoDB: Missing Ownership Check in MCP Attachment Read
Low
CVE-2026-47388
was published
for
nocodb
(npm)
Jun 5, 2026
NocoDB: Stale Auth Cache After API Token Deletion
Low
CVE-2026-46554
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: Attachment Size Limit Bypass via Upload-by-URL
Low
CVE-2026-46553
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
Low
CVE-2026-46549
was published
for
nocodb
(npm)
May 21, 2026
Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass
Low
CVE-2026-54326
was published
for
@earendil-works/pi-coding-agent
(npm)
Jun 16, 2026
Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
Low
CVE-2026-54327
was published
for
@earendil-works/pi-coding-agent
(npm)
Jun 17, 2026
HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because...
Low
Unreviewed
CVE-2026-26080
was published
Jul 20, 2026
The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of...
Low
Unreviewed
CVE-2026-10755
was published
Jul 20, 2026
A security vulnerability has been detected in itsourcecode Hospital Management System 1.0....
Low
Unreviewed
CVE-2026-16244
was published
Jul 20, 2026
Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity
Low
CVE-2026-54905
was published
for
concurrent-ruby
(RubyGems)
Jun 19, 2026
A flaw has been found in itsourcecode Courier Management System up to 1.0. Affected by this...
Low
Unreviewed
CVE-2026-16229
was published
Jul 19, 2026
A vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability...
Low
Unreviewed
CVE-2026-16220
was published
Jul 19, 2026
A security flaw has been discovered in davenardella snap7 up to 1.4.3. The impacted element is...
Low
Unreviewed
CVE-2026-16225
was published
Jul 19, 2026
A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1. Impacted is the function...
Low
Unreviewed
CVE-2026-16223
was published
Jul 19, 2026
A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. This issue affects some unknown...
Low
Unreviewed
CVE-2026-16222
was published
Jul 19, 2026
A flaw has been found in Croogo CMS up to 4.0.7. This affects the function FileManager:...
Low
Unreviewed
CVE-2026-16219
was published
Jul 19, 2026
A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this...
Low
Unreviewed
CVE-2026-16217
was published
Jul 19, 2026
ProTip!
Advisories are also available from the
GraphQL API