GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,029
Maven
5,000+
npm
5,000+
NuGet
976
pip
5,000+
Pub
13
RubyGems
1,070
Rust
1,404
Swift
61
Unreviewed advisories
All unreviewed
5,000+
2,289 advisories
Filter by severity
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
Moderate
CVE-2026-9595
was published
for
webpack-dev-server
(npm)
Jun 17, 2026
Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads
Moderate
CVE-2026-5038
was published
for
multer
(npm)
Jun 17, 2026
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Moderate
CVE-2026-54316
was published
for
@anthropic-ai/claude-code
(npm)
Jun 17, 2026
NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint
Moderate
CVE-2026-53931
was published
for
nocodb
(npm)
Jun 17, 2026
NocoDB: Server-Side Request Forgery via Base Migration URL
Moderate
CVE-2026-53930
was published
for
nocodb
(npm)
Jun 17, 2026
NocoDB: Stored Cross-Site Scripting via Secure Attachment
Moderate
CVE-2026-53929
was published
for
nocodb
(npm)
Jun 17, 2026
NocoDB: Refresh Tokens Persist Through Password Recovery
Moderate
CVE-2026-53928
was published
for
nocodb
(npm)
Jun 17, 2026
NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL
Moderate
CVE-2026-53927
was published
for
nocodb
(npm)
Jun 17, 2026
Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory
Moderate
CVE-2026-53765
was published
for
chrome-devtools-mcp
(npm)
Jun 17, 2026
n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints
Moderate
GHSA-664h-gpgq-h6xx
was published
for
n8n
(npm)
Jun 17, 2026
Pi Agent: Pi loads project-local extensions without approval
Moderate
CVE-2026-54325
was published
for
@earendil-works/pi-coding-agent
(npm)
Jun 17, 2026
@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g)
Moderate
CVE-2026-49993
was published
for
@nuxt/rspack-builder
(npm)
Jun 16, 2026
n8n: Denial of Service via ZIP decompression in webhook workflow
Moderate
CVE-2026-54314
was published
for
n8n
(npm)
Jun 16, 2026
n8n: Public API Execution Retry Authorization Bypass
Moderate
GHSA-h3jj-5f3v-3685
was published
for
n8n
(npm)
Jun 16, 2026
n8n: Python Code Node AST Validator Bypass
Moderate
GHSA-jwm3-qcfw-c5pp
was published
for
n8n
(npm)
Jun 16, 2026
n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
Moderate
CVE-2026-54303
was published
for
n8n
(npm)
Jun 16, 2026
n8n: Merge Node SQL Mode Prototype Pollution
Moderate
CVE-2026-54311
was published
for
n8n
(npm)
Jun 16, 2026
n8n: Prototype Pollution enables confused-deputy execution via public webhooks
Moderate
CVE-2026-54306
was published
for
n8n
(npm)
Jun 16, 2026
n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
Moderate
CVE-2026-54308
was published
for
n8n
(npm)
Jun 16, 2026
n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
Moderate
GHSA-hv7x-3x78-gx53
was published
for
n8n
(npm)
Jun 16, 2026
n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
Moderate
CVE-2026-54313
was published
for
n8n
(npm)
Jun 16, 2026
n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
Moderate
CVE-2026-54310
was published
for
n8n
(npm)
Jun 16, 2026
n8n: Git Node Clone and Push Operations Bypass File Sandbox
Moderate
CVE-2026-49465
was published
for
n8n
(npm)
Jun 16, 2026
Astro: XSS via Unescaped Attribute Names in Spread Props
Moderate
CVE-2026-54298
was published
for
astro
(npm)
Jun 16, 2026
@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config
Moderate
CVE-2026-54300
was published
for
@astrojs/netlify
(npm)
Jun 16, 2026
ProTip!
Advisories are also available from the
GraphQL API