GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,227
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,502
Pub
12
RubyGems
995
Rust
1,187
Swift
51
Unreviewed advisories
All unreviewed
5,000+
3,799 advisories
Filter by severity
Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters
Critical
CVE-2026-30863
was published
for
parse-server
(npm)
Mar 9, 2026
Apache IoTDB has an Insecure Default Configuration Vulnerability
Critical
CVE-2026-24015
was published
for
org.apache.iotdb:iotdb-core
(Maven)
Mar 9, 2026
Apache IoTDB has an Improper Input Validation vulnerability
Critical
CVE-2026-24713
was published
for
org.apache.iotdb:iotdb-core
(Maven)
Mar 9, 2026
OneUptime: Synthetic Monitor RCE via exposed Playwright browser object
Critical
CVE-2026-30921
was published
for
@oneuptime/common
(npm)
Mar 7, 2026
OneUpTime's Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCE
Critical
CVE-2026-30887
was published
for
@oneuptime/common
(npm)
Mar 7, 2026
SiYuan Vulnerable to Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakage
Critical
CVE-2026-30869
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 7, 2026
WeKnora has Remote Code Execution (RCE) via Command Injection in MCP Stdio Configuration Validation
Critical
CVE-2026-30861
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 7, 2026
WeKnora Vulnerable to Remote Code Execution via SQL Injection Bypass in AI Database Query Tool
Critical
CVE-2026-30860
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 6, 2026
WeKnora Vulnerable to Broken Access Control in Tenant Management
Critical
CVE-2026-30855
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 6, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import
Critical
CVE-2026-30832
was published
for
github.com/charmbracelet/soft-serve
(Go)
Mar 6, 2026
`time-sync` was removed from crates.io due to malicious code
Critical
GHSA-mh23-rw7f-v5pq
was published
for
time-sync
(Rust)
Mar 5, 2026
Pingora has HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing
Critical
CVE-2026-2835
was published
for
pingora-core
(Rust)
Mar 5, 2026
Pingora vulnerable to HTTP Request Smuggling via Premature Upgrade
Critical
CVE-2026-2833
was published
for
pingora-core
(Rust)
Mar 5, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification
Critical
CVE-2026-25921
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure
Critical
CVE-2026-27944
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 5, 2026
`dnp3times` was removed from crates.io due to malicious code
Critical
GHSA-xhw7-jhmp-j62j
was published
for
dnp3times
(Rust)
Mar 5, 2026
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
Critical
GHSA-5wp8-q9mx-8jx8
was published
for
zeptoclaw
(Rust)
Mar 5, 2026
Duplicate Advisory: HTTP Request Smuggling via Premature Upgrade
Critical
GHSA-f9v3-j2m7-4hpg
was published
for
pingora-core
(Rust)
Mar 5, 2026
•
withdrawn
Duplicate Advisory: HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing
Critical
GHSA-262p-vjx5-45xh
was published
for
pingora-core
(Rust)
Mar 5, 2026
•
withdrawn
pac4j-jwt: JwtAuthenticator Authentication Bypass via JWE-Wrapped PlainJWT
Critical
CVE-2026-29000
was published
for
org.pac4j:pac4j-jwt
(Maven)
Mar 5, 2026
ZITADEL has 1-Click Account Takeover via XSS in /saml-post Endpoint
Critical
CVE-2026-29191
was published
for
github.com/zitadel/zitadel
(Go)
Mar 4, 2026
File Browser's TUS Delete Endpoint Bypasses Delete Permission Check
Critical
CVE-2026-29188
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 4, 2026
SiYuan: Unauthenticated Reflected XSS via SVG Injection in /api/icon/getDynamicIcon Endpoint
Critical
CVE-2026-29183
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 4, 2026
`time_calibrators` was removed from crates.io due to malicious code
Critical
GHSA-wf45-3gpw-vrqv
was published
for
time_calibrators
(Rust)
Mar 4, 2026
`time_calibrator` was removed from crates.io due to malicious code
Critical
GHSA-77xj-rrh3-wx3v
was published
for
time_calibrator
(Rust)
Mar 4, 2026
ProTip!
Advisories are also available from the
GraphQL API