Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,180 advisories

Loading
pgAdmin 4: Improper restriction of excessive authentication attempts Moderate
CVE-2026-7820 was published for pgadmin4 (pip) May 11, 2026
GPT-Pilot contains a command injection vulnerability in the Executor.run() method Moderate
CVE-2026-31246 was published for gpt-pilot (pip) May 11, 2026
oxidize-pdf: NaN/inf bypass in colour content-stream emission causes PDF rejection (DoS) Moderate
GHSA-88q9-cmp2-c2vq was published for OxidizePdf.NET (NuGet) May 11, 2026
bzsanti Credited to bzsanti
bg0d-glitch Credited to bg0d-glitch
Keylime has a hardcoded attestation challenge nonce that allows replay attacks Moderate
CVE-2026-6420 was published for keylime (pip) May 11, 2026
Streamlink has an arbitrary local file read via file:// URI in HLS and DASH Moderate
CVE-2026-44353 was published for streamlink (pip) May 11, 2026
4tkD0g Credited to 4tkD0g and bastimeyer bastimeyer bastimeyer
Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission Moderate
CVE-2026-44571 was published for open-webui (pip) May 11, 2026
odgrso Credited to odgrso
PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries Moderate
CVE-2026-44337 was published for PraisonAI (pip) May 11, 2026
shmulc8 Credited to shmulc8
Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL Moderate
CVE-2026-41018 was published for apache-airflow-providers-elasticsearch (pip) May 11, 2026
Apache Airflow Providers OpenSearch: OpenSearch task-log handler leaks credentials embedded in the host URL Moderate
CVE-2026-43826 was published for apache-airflow-providers-opensearch (pip) May 11, 2026
Mistune Heading ID Attribute has Injection XSS Moderate
CVE-2026-44897 was published for mistune (pip) May 9, 2026
QiaoNPC Credited to QiaoNPC and Across-Verticals-Malaysia Across-Verticals-Malaysia Across-Verticals-Malaysia
Mistune has XSS via unescaped figclass/figwidth in Figure directive Moderate
CVE-2026-44896 was published for mistune (pip) May 8, 2026
sergeykochanov Credited to sergeykochanov
Mistune Math Plugin has an XSS Escape Bypass Moderate
CVE-2026-44708 was published for mistune (pip) May 8, 2026
QiaoNPC Credited to QiaoNPC and Across-Verticals-Malaysia Across-Verticals-Malaysia Across-Verticals-Malaysia
eml_parser has recursion DoS via nested message/rfc822 attachments Moderate
CVE-2026-44844 was published for eml_parser (pip) May 8, 2026
Sebasteuo Credited to Sebasteuo
Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order Moderate
CVE-2026-44568 was published for open-webui (pip) May 8, 2026
morimori-dev Credited to morimori-dev and Classic298 Classic298 Classic298
Wagtail has improper permission handling when copying pages Moderate
CVE-2026-44200 was published for wagtail (pip) May 8, 2026
RealOrangeOne Credited to RealOrangeOne and thesanjok thesanjok thesanjok
Wagtail has improper restriction handling on Documents and Images API Moderate
CVE-2026-44201 was published for wagtail (pip) May 8, 2026
thesanjok Credited to thesanjok and RealOrangeOne RealOrangeOne RealOrangeOne
Wagtail has improper permission handling when deleting form submissions Moderate
CVE-2026-44199 was published for wagtail (pip) May 8, 2026
RealOrangeOne Credited to RealOrangeOne and shukla304 shukla304 shukla304
Wagtail has improper permission handling when viewing page history Moderate
CVE-2026-44198 was published for wagtail (pip) May 8, 2026
RealOrangeOne Credited to RealOrangeOne and seoyoung-kang seoyoung-kang seoyoung-kang
Wagtail has improper permission handling when comparing revisions Moderate
CVE-2026-44197 was published for wagtail (pip) May 8, 2026
RealOrangeOne Credited to RealOrangeOne and seoyoung-kang seoyoung-kang seoyoung-kang
Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search Moderate
CVE-2026-44560 was published for open-webui (pip) May 8, 2026
Classic298 Credited to Classic298
Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels Moderate
CVE-2026-44561 was published for open-webui (pip) May 8, 2026
Classic298 Credited to Classic298
Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO Moderate
CVE-2026-44564 was published for open-webui (pip) May 8, 2026
Classic298 Credited to Classic298
Classic298 Credited to Classic298
ProTip! Advisories are also available from the GraphQL API