Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5 advisories

Loading
motionEye's missing authentication on ActionHandler allows unauthenticated camera action execution Moderate
CVE-2026-55863 was published for motioneye (pip) Jun 23, 2026
alanturing881 Credited to alanturing881, MichaIng, zagrim, Marijn0, and C4spr0x1A MichaIng MichaIng
zagrim zagrim Marijn0 Marijn0 C4spr0x1A C4spr0x1A
motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read High
CVE-2026-55488 was published for motioneye (pip) Jun 23, 2026
pizza-power Credited to pizza-power, sermikr0, C4spr0x1A, MichaIng, and alanturing881 sermikr0 sermikr0
C4spr0x1A C4spr0x1A MichaIng MichaIng alanturing881 alanturing881
ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components Low
CVE-2026-55671 was published for github.com/zitadel/zitadel (Go) Jun 18, 2026
wooseokdotkim Credited to wooseokdotkim, IAM-marco, livio-a, 0xBassia, alanturing881, dungNHVhust, sondt99, DavidCarliez, tikket1, Wernerina, morimori-dev, and vamsik2k5 IAM-marco IAM-marco
livio-a livio-a 0xBassia 0xBassia alanturing881 alanturing881 dungNHVhust dungNHVhust sondt99 sondt99 DavidCarliez DavidCarliez tikket1 tikket1 Wernerina Wernerina morimori-dev morimori-dev vamsik2k5 vamsik2k5
File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope Moderate
CVE-2026-54094 was published for github.com/filebrowser/filebrowser (Go) Jun 12, 2026
DavidCarliez Credited to DavidCarliez, hacdias, m2hcz, and alanturing881 hacdias hacdias
m2hcz m2hcz alanturing881 alanturing881
Firefly II has Stored XSS in Audit Log Entry view via piggy bank name (ale.twig) Moderate
GHSA-6jq6-x4cx-qvcm was published for grumpydictator/firefly-iii (Composer) Jun 12, 2026
alanturing881 Credited to alanturing881
ProTip! Advisories are also available from the GraphQL API