Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

132,662 advisories

Loading
The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the ... High Unreviewed
CVE-2026-4348 was published May 7, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints High
CVE-2026-34403 was published for github.com/0xJacky/Nginx-UI (Go) Apr 21, 2026
CE2Sec Credited to CE2Sec
PJUllrich Credited to PJUllrich, mtrudel, and maennchen mtrudel mtrudel
maennchen maennchen
Bandit's unbounded WebSocket inflate causes BEAM OOM with a single frame High
CVE-2026-39804 was published for bandit (Erlang) May 7, 2026
PJUllrich Credited to PJUllrich, mtrudel, and maennchen mtrudel mtrudel
maennchen maennchen
hickory-proto: NSEC3 closest-encloser proof validation enters unbounded loop on cross-zone responses High
GHSA-3v94-mw7p-v465 was published for hickory-net (Rust) May 7, 2026
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization High
CVE-2026-42402 was published for org.apache.neethi:neethi (Maven) May 1, 2026
Apache Neethi does not properly detect circular references in policy definitions. High
CVE-2026-42403 was published for org.apache.neethi:neethi (Maven) May 1, 2026
rust-zserio has Unbounded Memory Allocation High
GHSA-fpf5-4jw8-67x8 was published for rust-zserio (Rust) May 7, 2026
Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure High
GHSA-fc67-c4hg-q653 was published for github.com/aws/amazon-ecs-agent (Go) May 7, 2026
Krayin CRM allows a remote attacker to execute arbitrary code via compose email function High
CVE-2026-36340 was published for krayin/laravel-crm (Composer) Apr 30, 2026
ProTip! Advisories are also available from the GraphQL API