Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,795 advisories

Loading
jsii-diff: Command Injection via npm: package argument High
CVE-2026-15895 was published for jsii-diff (npm) Aug 7, 2026
Dremig Credited to Dremig
ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633 High
GHSA-w9hm-4m3m-fxmm was published for ngx-extended-pdf-viewer (npm) Aug 6, 2026
calixteman Credited to calixteman
PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF High
CVE-2026-16633 was published for pdfjs-dist (npm) Aug 6, 2026
wlayzz Credited to wlayzz
0xsharz Credited to 0xsharz
Nx: Zip-Slip in the self-hosted remote cache High
CVE-2026-71476 was published for @nx/azure-cache (npm) Aug 6, 2026
dinhvaren Credited to dinhvaren
quantumshiro Credited to quantumshiro
Pig-Tail Credited to Pig-Tail, sec-reex, and DavidCarliez sec-reex sec-reex
DavidCarliez DavidCarliez
manop55555 Credited to manop55555
Ciarands Credited to Ciarands
Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads High
CVE-2026-70604 was published for electron (npm) Aug 5, 2026
proxydom Credited to proxydom
Electron: Context isolation bypass via Function.prototype.bind hijack High
CVE-2026-70601 was published for electron (npm) Aug 5, 2026
XSS in Ghost's ActivityPub client High
CVE-2026-53950 was published for @tryghost/activitypub (npm) Aug 4, 2026
bgeesaman Credited to bgeesaman
berkdedekarginoglu Credited to berkdedekarginoglu
Flowise: Missing Authorization on Execution Update Endpoint High
CVE-2026-70475 was published for flowise (npm) Aug 4, 2026
Dimpyj1604 Credited to Dimpyj1604
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak High
CVE-2026-70474 was published for flowise (npm) Aug 4, 2026
hett-patell Credited to hett-patell
truongvip1 Credited to truongvip1
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store High
CVE-2026-70472 was published for flowise (npm) Aug 4, 2026
Kazamayc Credited to Kazamayc
Mirr2 Credited to Mirr2
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure High
CVE-2026-70471 was published for flowise (npm) Aug 4, 2026
EaEa0001 Credited to EaEa0001
leoelsolh Credited to leoelsolh
Aviral2642 Credited to Aviral2642
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses High
CVE-2026-69257 was published for flowise (npm) Aug 4, 2026
feiyang666 Credited to feiyang666
ProTip! Advisories are also available from the GraphQL API