GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
32 advisories
Filter by severity
Flowise: Mass Assignment in PUT /api/v1/user Allows Authenticated Users to Override Password Hash and Bypass Password Change Verification
Moderate
GHSA-59fh-9f3p-7m39
was published
for
flowise
(npm)
May 20, 2026
Drupal core allows Object Injection
Moderate
CVE-2026-6366
was published
for
drupal/core
(Composer)
May 20, 2026
Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation
Moderate
CVE-2026-45396
was published
for
open-webui
(pip)
May 14, 2026
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
Moderate
CVE-2026-42044
was published
for
axios
(npm)
May 5, 2026
Kimai's User Preferences API allows standard users to modify restricted attributes: hourly_rate, internal_rate
Moderate
CVE-2026-40486
was published
for
kimai/kimai
(Composer)
Apr 15, 2026
Parse Server session creation endpoint allows overwriting server-generated session fields
Moderate
CVE-2026-32742
was published
for
parse-server
(npm)
Mar 17, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
Moderate
CVE-2026-31815
was published
for
django-unicorn
(pip)
Mar 11, 2026
Craft CMS: Entries Authorship Spoofing via Mass Assignment
Moderate
CVE-2026-28781
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Svelte SSR attribute spreading includes inherited properties from prototype chain
Moderate
CVE-2026-27125
was published
for
svelte
(npm)
Feb 19, 2026
An unauthenticated device registration vulnerability, caused by Improperly Controlled...
Moderate
Unreviewed
CVE-2025-9315
was published
Dec 10, 2025
mdast-util-to-hast has unsanitized class attribute
Moderate
CVE-2025-66400
was published
for
mdast-util-to-hast
(npm)
Dec 2, 2025
Drupal core allows Object Injection
Moderate
CVE-2025-13081
was published
for
drupal/core
(Composer)
Nov 18, 2025
A mass assignment vulnerability exists in danny-avila/librechat, affecting all versions. This...
Moderate
Unreviewed
CVE-2025-7104
was published
Sep 29, 2025
Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability
Moderate
CVE-2025-31674
was published
for
drupal/core
(Composer)
Apr 1, 2025
In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation...
Moderate
Unreviewed
CVE-2024-10359
was published
Mar 20, 2025
A vulnerability that poses a potential risk of polluting the MXsecurity sqlite database and the...
Moderate
Unreviewed
CVE-2023-39983
was published
Sep 2, 2023
The Cloud Functions subsystem in OpenTrace 1.0 might allow fabrication attacks by making billions...
Moderate
Unreviewed
CVE-2020-11872
was published
May 24, 2022
Improperly Controlled Modification of Dynamically-Determined Object Attributes in express-mock-middleware
Moderate
CVE-2020-7616
was published
for
express-mock-middleware
(npm)
Dec 9, 2021
Prototype Pollution in the merge and clone helper methods
Moderate
CVE-2021-39227
was published
for
zrender
(npm)
Sep 20, 2021
Prototype Pollution in open-graph
Moderate
CVE-2021-23419
was published
for
open-graph
(npm)
Sep 1, 2021
Prototype Pollution in deepmergefn
Moderate
CVE-2021-23417
was published
for
deepmergefn
(npm)
Aug 10, 2021
Remote Code Execution via unsafe classes in otherwise permitted modules
Moderate
CVE-2021-32807
was published
for
AccessControl
(pip)
Aug 5, 2021
eivindfjeldstad-dot contains prototype pollution vulnerability
Moderate
CVE-2020-7639
was published
for
@eivifj/dot
(npm)
May 25, 2021
Prototype pollution in @tsed/core
Moderate
CVE-2020-7748
was published
for
@tsed/core
(npm)
May 10, 2021
ProTip!
Advisories are also available from the
GraphQL API