Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,562 advisories

Loading
Directus has a DOM-Based cross-site scripting (XSS) via layout_options Low
CVE-2024-6533 was published for directus (npm) Jan 23, 2025
Amayyas Credited to Amayyas
sec-reex Credited to sec-reex and LlewxamDev LlewxamDev LlewxamDev
connorshea Credited to connorshea
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController) Low
CVE-2026-73427 was published for action_text-trix (RubyGems) Mar 29, 2026
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect Low
CVE-2026-59730 was published for @astrojs/node (npm) Jul 20, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands Low
CVE-2026-59727 was published for astro (npm) Jul 20, 2026
jlgore Credited to jlgore
Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads Low
CVE-2026-41694 was published for org.springframework.security:spring-security-saml2-service-provider (Maven) Jun 10, 2026
Keras: tar extraction permits symlink-based path traversal Low
CVE-2026-12482 was published for keras (pip) Jul 14, 2026
Django: signed cookies are vulnerable to salt namespace collisions Low
CVE-2026-6873 was published for django (pip) Jun 3, 2026
cgurnik Credited to cgurnik
cgurnik Credited to cgurnik and hahwul hahwul hahwul
Django: has_vary_header may expose cached responses when Vary values contain whitespace Low
CVE-2026-48587 was published for django (pip) Jun 3, 2026
cgurnik Credited to cgurnik
cgurnik Credited to cgurnik
Hono: Proxy Helper does not remove response headers listed in the `Connection` header Low
CVE-2026-71849 was published for hono (npm) Aug 7, 2026
morgan-coded Credited to morgan-coded
Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read Low
CVE-2026-56394 was published for craftcms/cms (Composer) Jul 9, 2026
GCXWLP Credited to GCXWLP
GCXWLP Credited to GCXWLP
Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options Low
CVE-2026-56393 was published for craftcms/cms (Composer) Mar 3, 2026
mHe4am Credited to mHe4am
Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page Low
CVE-2026-56381 was published for craftcms/cms (Composer) Mar 11, 2026
mHe4am Credited to mHe4am
Craft CMS: Incorrect path validation could potentially lead to path traversal Low
GHSA-7hxc-f267-h5q7 was published for craftcms/cms (Composer) Aug 6, 2026
Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type Low
CVE-2026-56383 was published for craftcms/cms (Composer) Feb 25, 2026
mHe4am Credited to mHe4am
Mermaid configuration APIs allow prototype pollution Low
CVE-2026-71438 was published for mermaid (npm) Aug 6, 2026
Str1ckl4nd Credited to Str1ckl4nd, Zyy0530, 7thParkk, mauriceng98, and aloisklink Zyy0530 Zyy0530
7thParkk 7thParkk mauriceng98 mauriceng98 aloisklink aloisklink
Contao: Possible path traversal in job download URIs Low
CVE-2026-55825 was published for contao/contao (Composer) Aug 6, 2026
0x1saac Credited to 0x1saac
Contao crawler leaks auth credentials to external hosts Low
CVE-2026-55824 was published for contao/contao (Composer) Aug 6, 2026
0x1saac Credited to 0x1saac
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing Low
CVE-2026-71326 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
hussst Credited to hussst
ProTip! Advisories are also available from the GraphQL API