GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,795 advisories
Filter by severity
jsii-diff: Command Injection via npm: package argument
High
CVE-2026-15895
was published
for
jsii-diff
(npm)
Aug 7, 2026
ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633
High
GHSA-w9hm-4m3m-fxmm
was published
for
ngx-extended-pdf-viewer
(npm)
Aug 6, 2026
PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF
High
CVE-2026-16633
was published
for
pdfjs-dist
(npm)
Aug 6, 2026
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
High
GHSA-5p4m-2wfm-xmqj
was published
for
js-yaml
(npm)
Aug 6, 2026
Nx: Zip-Slip in the self-hosted remote cache
High
CVE-2026-71476
was published
for
@nx/azure-cache
(npm)
Aug 6, 2026
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
High
CVE-2026-71321
was published
for
nuxt
(npm)
Aug 5, 2026
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
High
CVE-2026-71320
was published
for
nuxt
(npm)
Aug 5, 2026
Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
High
CVE-2026-71316
was published
for
nuxt
(npm)
Aug 5, 2026
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
High
CVE-2026-71315
was published
for
nuxt
(npm)
Aug 5, 2026
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
High
CVE-2026-71314
was published
for
nuxt
(npm)
Aug 5, 2026
Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
High
CVE-2026-70608
was published
for
electron
(npm)
Aug 5, 2026
Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
High
CVE-2026-70604
was published
for
electron
(npm)
Aug 5, 2026
Electron: Context isolation bypass via Function.prototype.bind hijack
High
CVE-2026-70601
was published
for
electron
(npm)
Aug 5, 2026
XSS in Ghost's ActivityPub client
High
CVE-2026-53950
was published
for
@tryghost/activitypub
(npm)
Aug 4, 2026
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
High
CVE-2026-70476
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Missing Authorization on Execution Update Endpoint
High
CVE-2026-70475
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
High
CVE-2026-70474
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
High
CVE-2026-70473
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
High
CVE-2026-70472
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
High
GHSA-88pr-878c-24wf
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
High
CVE-2026-70471
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
High
CVE-2026-69263
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
High
CVE-2026-69262
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
High
CVE-2026-69258
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
High
CVE-2026-69257
was published
for
flowise
(npm)
Aug 4, 2026
ProTip!
Advisories are also available from the
GraphQL API