Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

270 advisories

Loading
OpenAM Insecure SSO Cookie Initialization High
CVE-2026-53660 was published for org.openidentityplatform.openam:openam-core (Maven) Aug 14, 2026
wodzen Credited to wodzen
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing Critical
CVE-2026-66066 was published for activestorage (RubyGems) Jul 30, 2026
0xacb Credited to 0xacb, Ry0taK, flavorjones, jeremy, byroot, ethiack-admin, s3np41k1r1t0, castilho101, and rafaelfranca Ry0taK Ry0taK
flavorjones flavorjones jeremy jeremy byroot byroot ethiack-admin ethiack-admin s3np41k1r1t0 s3np41k1r1t0 castilho101 castilho101 rafaelfranca rafaelfranca
Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover Critical
CVE-2026-52824 was published for kimai/kimai (Composer) Jul 14, 2026
AzureADTrent Credited to AzureADTrent
SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML() Critical
CVE-2026-54158 was published for github.com/siyuan-note/siyuan/kernel (Go) Jul 10, 2026
hillalee Credited to hillalee
SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet() Critical
CVE-2026-54067 was published for github.com/siyuan-note/siyuan/kernel (Go) Jul 10, 2026
hillalee Credited to hillalee
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894 High
CVE-2026-54066 was published for github.com/siyuan-note/siyuan/kernel (Go) Jul 10, 2026
aslein1413-sys Credited to aslein1413-sys
subhanUmer Credited to subhanUmer
nono-py vulnerable to authorization bypass / policy confusion Moderate
GHSA-9j7f-3r4p-pwh6 was published for nono-py (pip) Jun 26, 2026
OpenAM Authentication Bypass via MSISDN LDAP Injection High
CVE-2026-46619 was published for org.openidentityplatform.openam:openam-auth-msisdn (Maven) Jun 26, 2026
wodzen Credited to wodzen
MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies Moderate
CVE-2026-48509 was published for MessagePack (NuGet) Jun 25, 2026
AArnott Credited to AArnott
AArnott Credited to AArnott
ProTip! Advisories are also available from the GraphQL API