GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
339,386 advisories
Filter by severity
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
Critical
CVE-2026-44990
was published
for
sanitize-html
(npm)
May 14, 2026
@apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input
Moderate
CVE-2026-42853
was published
for
@apostrophecms/cli
(npm)
May 14, 2026
@agenticmail/mcp Missing Authentication for Critical Function
High
CVE-2026-50287
was published
for
@agenticmail/mcp
(npm)
Jun 1, 2026
Koel Vulnerable to SSRF via Podcast Episode Enclosure URLs
High
CVE-2026-47260
was published
for
phanan/koel
(Composer)
May 29, 2026
actual Allows Electron to Run As Node
Moderate
CVE-2026-42890
was published
for
actual
(npm)
Jun 8, 2026
Parse Server's GraphQL "Did you mean ...?" validation suggestions disclose schema to unauthenticated callers
Moderate
CVE-2026-47248
was published
for
parse-server
(npm)
May 29, 2026
Parse Server: Pre-authentication denial of service via client version header regex backtracking
High
CVE-2026-47138
was published
for
parse-server
(npm)
May 23, 2026
Docker: Race condition in docker cp allows bind mount redirection to host path
High
CVE-2026-42306
was published
for
github.com/docker/docker
(Go)
May 18, 2026
Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap
Moderate
CVE-2026-41568
was published
for
github.com/docker/docker
(Go)
May 18, 2026
File Browser has incorrect access control for public directory shares via rule path rebasing
High
CVE-2026-54091
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames
Moderate
CVE-2026-54093
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
Moderate
CVE-2026-54094
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser has a DoS Vulnerability via Public Login API
High
CVE-2026-54092
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
High
CVE-2026-41731
was published
for
org.springframework.kafka:spring-kafka
(Maven)
Jun 10, 2026
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
Moderate
CVE-2026-41726
was published
for
org.springframework.kafka:spring-kafka
(Maven)
Jun 10, 2026
A path traversal vulnerability has been reported to affect several QNAP operating system versions...
Moderate
Unreviewed
CVE-2026-24717
was published
Jun 10, 2026
A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers...
High
Unreviewed
CVE-2026-26237
was published
Jun 10, 2026
A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then...
High
Unreviewed
CVE-2026-42947
was published
Jun 12, 2026
Naxclow devices use a server-side, per-device relay credential that never rotates and is re...
Critical
Unreviewed
CVE-2026-50101
was published
Jun 12, 2026
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4...
High
Unreviewed
CVE-2026-53408
was published
Jun 12, 2026
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4...
High
Unreviewed
CVE-2026-53407
was published
Jun 12, 2026
Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters,...
Moderate
Unreviewed
CVE-2026-42932
was published
Jun 12, 2026
The Naxclow platform API that returns device relay registration details exposes a persistent...
High
Unreviewed
CVE-2026-50108
was published
Jun 12, 2026
MISP contains a path traversal vulnerability in OrganisationsController::getOrgLogo. The...
Moderate
Unreviewed
CVE-2026-54394
was published
Jun 12, 2026
Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft...
Moderate
Unreviewed
CVE-2026-10715
was published
Jun 12, 2026
ProTip!
Advisories are also available from the
GraphQL API