Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,237 advisories

Loading
Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization Moderate
CVE-2026-44311 was published for fabric (npm) Jun 12, 2026
Budibase: Unvalidated VectorDB Host Parameter Enables SSRF Moderate
CVE-2026-48148 was published for @budibase/server (npm) Jun 12, 2026
fg0x0 Credited to fg0x0
Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker Moderate
CVE-2026-48147 was published for @budibase/backend-core (npm) Jun 12, 2026
b-hermes Credited to b-hermes
Budibase: SSRF via User-Controlled queryId in Automation Execute Query Step Moderate
CVE-2026-48128 was published for budibase (npm) Jun 12, 2026
fg0x0 Credited to fg0x0
LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access Moderate
CVE-2026-48121 was published for @langchain/langgraph-checkpoint-mongodb (npm) Jun 12, 2026
Nagendhra-web Credited to Nagendhra-web, etairl, and hntrl etairl etairl
hntrl hntrl
@hapi/inert has a static-file confinement bypass via sibling-prefix path Moderate
CVE-2026-48049 was published for @hapi/inert (npm) Jun 11, 2026
imssm99 Credited to imssm99
joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas Moderate
CVE-2026-48038 was published for joi (npm) Jun 11, 2026
kexwin Credited to kexwin
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects Moderate
CVE-2026-48022 was published for @hapi/wreck (npm) Jun 11, 2026
SnailSploit Credited to SnailSploit
@hulumi/baseline: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture Moderate
CVE-2026-48037 was published for @hulumi/baseline (npm) Jun 10, 2026
kerberosmansour Credited to kerberosmansour
FUXA's scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions Moderate
CVE-2026-47721 was published for fuxa-server (npm) Jun 8, 2026
adrgs Credited to adrgs and aisafe-bot aisafe-bot aisafe-bot
FUXA has SQL Injection in its TDengine DAQ connector via backslash bypass of escapeTdString Moderate
CVE-2026-47720 was published for fuxa-server (npm) Jun 8, 2026
adrgs Credited to adrgs and aisafe-bot aisafe-bot aisafe-bot
actual Allows Electron to Run As Node Moderate
CVE-2026-42890 was published for actual (npm) Jun 8, 2026
mustafa-sec Credited to mustafa-sec
NocoDB: OAuth Tokens Persist Through Security Events Moderate
CVE-2026-53926 was published for nocodb (npm) Jun 5, 2026
bugbunny-research Credited to bugbunny-research
NocoDB: OAuth Authorization Code Race Condition Moderate
CVE-2026-47386 was published for nocodb (npm) Jun 5, 2026
NocoDB: Path Traversal via SQLite Source Filename Moderate
CVE-2026-47385 was published for nocodb (npm) Jun 5, 2026
Mouhebbenelwafi Credited to Mouhebbenelwafi
NocoDB: SQL Injection via Column Title in Bulk GroupBy Moderate
CVE-2026-47384 was published for nocodb (npm) Jun 5, 2026
geo-chen Credited to geo-chen
NocoDB: Server-Side Request Forgery via Database Connection Host Moderate
CVE-2026-47382 was published for nocodb (npm) Jun 5, 2026
helwor-01 Credited to helwor-01
NocoDB: Cross-Workspace Integration Use in Connection Test Moderate
CVE-2026-47381 was published for nocodb (npm) Jun 5, 2026
DongyangLyu Credited to DongyangLyu
NocoDB: Plaintext Password Comparison in Shared Views Moderate
CVE-2026-47379 was published for nocodb (npm) Jun 5, 2026
Proscan-one Credited to Proscan-one
NocoDB: Hidden Column Exposure in Public Shared View Endpoints Moderate
CVE-2026-47378 was published for nocodb (npm) Jun 5, 2026
0xBassia Credited to 0xBassia
NocoDB: Open Redirect via Hash Fragment in hashRedirect Plugin Moderate
CVE-2026-47377 was published for nocodb (npm) Jun 5, 2026
fg0x0 Credited to fg0x0
NocoDB: Reflected Cross-Site Scripting via Password Reset Token Moderate
CVE-2026-47376 was published for nocodb (npm) Jun 5, 2026
fg0x0 Credited to fg0x0
NocoDB: Postgres SQL Injection in Formula `ARRAYSORT` Moderate
CVE-2026-47375 was published for nocodb (npm) Jun 5, 2026
leduckhuong Credited to leduckhuong
NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints Moderate
CVE-2026-47279 was published for nocodb (npm) Jun 5, 2026
leduckhuong Credited to leduckhuong
MCP Server Kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltration Moderate
CVE-2026-47250 was published for mcp-server-kubernetes (npm) Jun 5, 2026
yotampe-pluto Credited to yotampe-pluto
ProTip! Advisories are also available from the GraphQL API