GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,821
Maven
5,000+
npm
5,000+
NuGet
939
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
6,204 advisories
Filter by severity
Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution
High
CVE-2026-45395
was published
for
open-webui
(npm)
May 14, 2026
open-webui Vulnerable to Stored XSS via Model Description
High
CVE-2026-44721
was published
for
open-webui
(npm)
May 8, 2026
Flowise has an MCP Security Bypass that Enables RCE
High
GHSA-m99r-2hxc-cp3q
was published
for
flowise
(npm)
May 14, 2026
nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect)
Low
CVE-2026-44589
was published
for
nuxt-og-image
(npm)
May 7, 2026
Strapi may leak sensitive data via relational filtering due to lack of query sanitization
Critical
CVE-2026-27886
was published
for
@strapi/strapi
(npm)
May 14, 2026
Strapi Upload Plugin MIME Validation Bypass via Content API
Moderate
CVE-2026-22707
was published
for
@strapi/upload
(npm)
May 14, 2026
Strapi: Password Reset Does Not Revoke Existing Refresh Sessions
Low
CVE-2026-22706
was published
for
@strapi/admin
(npm)
May 13, 2026
Strapi Vulnerable to SQL Injection in Content Type Builder
Critical
CVE-2026-22599
was published
for
@strapi/content-type-builder
(npm)
May 13, 2026
Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keying
Moderate
CVE-2025-64526
was published
for
@strapi/plugin-users-permissions
(npm)
May 13, 2026
@joplin/onenote-converter: Path traversal in OneNote importer allows overwriting arbitrary files
High
CVE-2026-22810
was published
for
@joplin/onenote-converter
(npm)
May 15, 2026
Budibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permission instead of builder access, allowing any authenticated app user to overwrite datasource connection parameters including host, port, and URL
High
CVE-2026-45717
was published
for
@budibase/server
(npm)
May 15, 2026
Budibase: SSRF Bypass via HTTP Redirect in REST Datasource Integration
High
CVE-2026-45715
was published
for
@budibase/server
(npm)
May 15, 2026
Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validation
High
CVE-2026-45548
was published
for
@budibase/server
(npm)
May 15, 2026
Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation
High
CVE-2026-45364
was published
for
better-auth
(npm)
May 15, 2026
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE
Moderate
GHSA-wxw3-q3m9-c3jr
was published
for
better-auth
(npm)
May 15, 2026
Svelte devalue: DoS via sparse array deserialization
High
CVE-2026-42570
was published
for
devalue
(npm)
May 14, 2026
Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order
High
CVE-2026-45665
was published
for
open-webui
(npm)
May 14, 2026
Sveltejs devalue's `devalue.parse` and `devalue.unflatten` emit objects with `__proto__` own properties
Low
GHSA-mwv9-gp5h-frr4
was published
for
devalue
(npm)
Mar 12, 2026
vm2 Has a Sandbox Breakout Using Async Generator
Critical
CVE-2026-45411
was published
for
vm2
(npm)
May 14, 2026
FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover
High
CVE-2026-46480
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover
High
CVE-2026-46479
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover
High
CVE-2026-46478
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover
High
CVE-2026-46477
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: CustomTemplate create+update mass-assignment allows cross-workspace template takeover
High
CVE-2026-46476
was published
for
flowise
(npm)
May 14, 2026
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @ranfdev/deepobj
High
CVE-2026-46509
was published
for
@ranfdev/deepobj
(npm)
May 14, 2026
ProTip!
Advisories are also available from the
GraphQL API