GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,029
Maven
5,000+
npm
5,000+
NuGet
976
pip
5,000+
Pub
13
RubyGems
1,070
Rust
1,404
Swift
61
Unreviewed advisories
All unreviewed
5,000+
6,517 advisories
Filter by severity
Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker
Moderate
CVE-2026-48147
was published
for
@budibase/backend-core
(npm)
Jun 12, 2026
Budibase: Unvalidated VectorDB Host Parameter Enables SSRF
Moderate
CVE-2026-48148
was published
for
@budibase/server
(npm)
Jun 12, 2026
Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
Critical
CVE-2026-48150
was published
for
@budibase/server
(npm)
Jun 12, 2026
Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
High
CVE-2026-48151
was published
for
@budibase/server
(npm)
Jun 12, 2026
Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL
High
CVE-2026-48152
was published
for
@budibase/server
(npm)
Jun 12, 2026
NocoDB: OAuth Tokens Persist Through Security Events
Moderate
CVE-2026-53926
was published
for
nocodb
(npm)
Jun 5, 2026
Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
High
CVE-2026-44486
was published
for
axios
(npm)
Jun 4, 2026
Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
High
CVE-2026-44487
was published
for
axios
(npm)
Jun 4, 2026
Allocation of Resources Without Limits or Throttling in Axios
High
CVE-2026-44488
was published
for
axios
(npm)
Jun 4, 2026
Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
Low
CVE-2026-44489
was published
for
axios
(npm)
May 29, 2026
axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
Moderate
CVE-2026-44490
was published
for
axios
(npm)
May 29, 2026
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
High
CVE-2026-44494
was published
for
axios
(npm)
May 29, 2026
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
High
CVE-2026-44495
was published
for
axios
(npm)
May 29, 2026
tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape
High
CVE-2026-44705
was published
for
tmp
(npm)
May 27, 2026
MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement
High
CVE-2026-46519
was published
for
mcp-server-kubernetes
(npm)
May 21, 2026
MCP Server Kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltration
Moderate
CVE-2026-47250
was published
for
mcp-server-kubernetes
(npm)
Jun 5, 2026
Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
Critical
CVE-2026-46703
was published
for
@boxlite-ai/boxlite
(Go)
May 21, 2026
BoxLite: Permission Bypass Allows Modification of Read-Only Files
Critical
CVE-2026-46695
was published
for
@boxlite-ai/boxlite
(Go)
May 21, 2026
joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas
Moderate
CVE-2026-48038
was published
for
joi
(npm)
Jun 11, 2026
Nuxt: Reflected XSS in `navigateTo()` external redirect
Moderate
CVE-2026-45669
was published
for
nuxt
(npm)
May 19, 2026
Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)
Moderate
CVE-2026-45670
was published
for
@nuxt/rspack-builder
(npm)
May 19, 2026
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
Low
CVE-2026-46342
was published
for
@nuxt/nitro-server
(npm)
May 19, 2026
Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`
Moderate
CVE-2026-47200
was published
for
@nuxt/nitro-server
(npm)
May 29, 2026
vm2 has a sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks
High
CVE-2026-47135
was published
for
vm2
(npm)
May 29, 2026
vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain
High
CVE-2026-47209
was published
for
vm2
(npm)
May 29, 2026
ProTip!
Advisories are also available from the
GraphQL API