Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7 advisories

Loading
NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion Moderate
CVE-2026-46551 was published for nocodb (npm) May 21, 2026
ik0z Credited to ik0z
NocoDB: Refresh Token Cookie Set Without `secure` and `sameSite` Flags Moderate
CVE-2026-46550 was published for nocodb (npm) May 21, 2026
ik0z Credited to ik0z
NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation Low
CVE-2026-46549 was published for nocodb (npm) May 21, 2026
ik0z Credited to ik0z
NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams) Moderate
CVE-2026-46548 was published for nocodb (npm) May 21, 2026
ik0z Credited to ik0z
edx-enterprise has SSRF via SAML metadata URL in sync_provider_data endpoint High
CVE-2026-42860 was published for edx-enterprise (pip) May 5, 2026
ik0z Credited to ik0z
phpMyFAQ: Stored XSS via Regex Bypass in Filter::removeAttributes() Moderate
CVE-2026-34729 was published for phpmyfaq/phpmyfaq (Composer) Apr 1, 2026
ik0z Credited to ik0z
phpMyFAQ: Path Traversal - Arbitrary File Deletion in MediaBrowserController High
CVE-2026-34728 was published for phpmyfaq/phpmyfaq (Composer) Apr 1, 2026
ik0z Credited to ik0z
ProTip! Advisories are also available from the GraphQL API