GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
43
Go
3,181
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,474
Pub
12
RubyGems
991
Rust
1,185
Swift
51
Unreviewed advisories
All unreviewed
5,000+
9,551 advisories
Filter by severity
Pocket ID: OIDC authorization code validation uses AND instead of OR, allowing cross-client token exchange
High
CVE-2026-28513
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Mar 9, 2026
Pocket ID: OAuth redirect_uri validation bypass via userinfo/host confusion
High
CVE-2026-28512
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Mar 9, 2026
@budibase/server: Command Injection in PostgreSQL Dump Command
High
CVE-2026-25041
was published
for
@budibase/server
(npm)
Mar 9, 2026
Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator
High
CVE-2025-69219
was published
for
apache-airflow-providers-http
(pip)
Mar 9, 2026
Apache ZooKeeper has improper handling of configuration values
High
CVE-2026-24308
was published
for
org.apache.zookeeper:zookeeper
(Maven)
Mar 7, 2026
Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
High
CVE-2026-24281
was published
for
org.apache.zookeeper:zookeeper
(Maven)
Mar 7, 2026
Meta Box Plugin for WordPress: Authenticated (Contributor+) Arbitrary File Deletion via ajax_delete_file
High
CVE-2025-14675
was published
for
wpmetabox/meta-box
(Composer)
Mar 7, 2026
Black's vulnerable version parsing leads to RCE in GitHub Action
High
CVE-2026-31900
was published
for
psf/black
(GitHub Actions)
Mar 7, 2026
FUXA has a hardcoded fallback JWT signing secret
High
GHSA-c8m8-3jcr-6rj5
was published
for
@frangoteam/fuxa
(npm)
Mar 7, 2026
mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft
High
GHSA-g9rg-8vq5-mpwm
was published
for
mcp-memory-service
(pip)
Mar 7, 2026
WeKnora has Broken Access Control - Cross-Tenant Data Exposure
High
CVE-2026-30859
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 6, 2026
WeKnora has DNS Rebinding Vulnerability in web_fetch Tool that Allows SSRF to Internal Resources
High
CVE-2026-30858
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 6, 2026
Caddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege Escalation
High
CVE-2026-30851
was published
for
github.com/caddyserver/caddy/v2/modules/caddyhttp/reverseproxy
(Go)
Mar 6, 2026
Flowise Missing Authentication on NVIDIA NIM Endpoints
High
CVE-2026-30824
was published
for
flowise
(npm)
Mar 6, 2026
Flowise has IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration
High
CVE-2026-30823
was published
for
flowise
(npm)
Mar 6, 2026
Flowise Allows Mass Assignment in `/api/v1/leads` Endpoint
High
CVE-2026-30822
was published
for
flowise
(npm)
Mar 6, 2026
Zarf's symlink targets in archives are not validated against destination directory
High
CVE-2026-29064
was published
for
github.com/zarf-dev/zarf/src/pkg/archive
(Go)
Mar 6, 2026
CoreDNS Loop Detection Denial of Service Vulnerability
High
CVE-2026-26018
was published
for
github.com/coredns/coredns
(Go)
Mar 6, 2026
Flowise has Arbitrary File Upload via MIME Spoofing
High
CVE-2026-30821
was published
for
flowise
(npm)
Mar 6, 2026
Flowise has Authorization Bypass via Spoofed x-request-from Header
High
CVE-2026-30820
was published
for
flowise
(npm)
Mar 6, 2026
parse-server's endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user
High
CVE-2026-30229
was published
for
parse-server
(npm)
Mar 6, 2026
PinchTab has SSRF with Full Response Exfiltration via Download Handler
High
CVE-2026-30834
was published
for
github.com/pinchtab/pinchtab/cmd/pinchtab
(Go)
Mar 6, 2026
express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network
High
CVE-2026-30827
was published
for
express-rate-limit
(npm)
Mar 6, 2026
Snipe-IT has sensitive user attributes related to account privileges that are insufficiently protected against mass assignment
High
CVE-2025-15602
was published
for
snipe/snipe-it
(Composer)
Mar 6, 2026
ProTip!
Advisories are also available from the
GraphQL API