Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,910 advisories

Loading
Snipe-IT: 2FA bypass via the API token flow High
CVE-2026-63493 was published for snipe/snipe-it (Composer) Sep 24, 2026
colinthebomb1 Credited to colinthebomb1
podman quadlet install --replace does not fully replace the old file Moderate
CVE-2026-19730 was published for github.com/containers/podman/v5 (Go) Sep 24, 2026
north-echo Credited to north-echo
Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files Moderate
CVE-2026-92164 was published for streamlink (pip) Sep 24, 2026
arpitjain099 Credited to arpitjain099 and bastimeyer bastimeyer bastimeyer
SunEditor: Critical XSS vulnerability - sanitizer bypass Critical
CVE-2026-59167 was published for suneditor (npm) Sep 24, 2026
Adyej999 Credited to Adyej999
REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration Moderate
CVE-2026-62998 was published for redaxo/source (Composer) Sep 24, 2026
de3erve-hunter Credited to de3erve-hunter
elysia has Inefficient Algorithmic Complexity and Interpretation Conflict High
CVE-2026-56669 was published for elysia (npm) Sep 23, 2026
jviide Credited to jviide
ReactPress has SQL injection via dynamic column names in TypeORM query builders High
CVE-2026-61685 was published for @fecommunity/reactpress (npm) Sep 23, 2026
lsr365400 Credited to lsr365400
plone.app.contenttypes has a Denial of Service in File Upload due to excessive filename length Moderate
GHSA-8pcw-h6w9-h46g was published for plone.app.contenttypes (pip) Sep 23, 2026
viliald Credited to viliald
plone.app.dexterity has a Denial of Service due to excessive title or description length Moderate
CVE-2026-57576 was published for plone.app.dexterity (pip) Sep 23, 2026
viliald Credited to viliald
OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget High
CVE-2026-77394 was published for @openc3/vue-common (npm) Sep 23, 2026
ArpitKubadia Credited to ArpitKubadia
Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS High
CVE-2026-82407 was published for github.com/klever-io/klever-go (Go) Sep 23, 2026
mabdullah22 Credited to mabdullah22
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery High
CVE-2026-82409 was published for github.com/klever-io/klever-go (Go) Sep 23, 2026
mabdullah22 Credited to mabdullah22
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace High
CVE-2026-82406 was published for github.com/klever-io/klever-go (Go) Sep 23, 2026
mabdullah22 Credited to mabdullah22
Formie: Missing authorization on sent notification resend modal exposes submission PII High
CVE-2026-76089 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Jawn: Quadratic parsing effort in AsyncParser High
CVE-2026-61814 was published for org.typelevel:jawn-parser_2.12 (Maven) Sep 23, 2026
rossabaker Credited to rossabaker and samspills samspills samspills
Jawn: Uncontrolled nesting depth in JSON parser High
CVE-2026-59990 was published for org.typelevel:jawn-parser_2.12 (Maven) Sep 23, 2026
rossabaker Credited to rossabaker and eed3si9n eed3si9n eed3si9n
mabdullah22 Credited to mabdullah22
ch4r0utf8 Credited to ch4r0utf8
Klever-Go: /log controls global node logging High
CVE-2026-86064 was published for github.com/klever-io/klever-go (Go) Sep 23, 2026
Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint Moderate
CVE-2026-93421 was published for mesop (pip) Sep 23, 2026
5H4D0WBY73 Credited to 5H4D0WBY73
OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting High
CVE-2026-77601 was published for openc3 (RubyGems) Sep 23, 2026
Marnick39 Credited to Marnick39
Wire Swift runtime: negative LENGTH_DELIMITED length in skipGroup() crashes any protobuf-decoding service High
CVE-2026-61695 was published for github.com/square/wire (Swift) Sep 23, 2026
tonghuaroot Credited to tonghuaroot
Formie: Unauthenticated users can overwrite incomplete submissions via submit action High
CVE-2026-76087 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials High
CVE-2026-76086 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
ProTip! Advisories are also available from the GraphQL API