Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

330 advisories

Loading
Netty: Security Control Bypass via CORS Short-Circuit Failure Moderate
CVE-2026-56746 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
violetagg Credited to violetagg
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints Moderate
CVE-2026-58429 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Pcat2003 Credited to Pcat2003
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint Moderate
CVE-2026-58507 was published for code.gitea.io/gitea (Go) Jul 21, 2026
prakhar0x01 Credited to prakhar0x01
Decidim: Forms admin question editor lacks authorization Moderate
CVE-2026-45086 was published for decidim-demographics (RubyGems) Jul 13, 2026
Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data Moderate
GHSA-382c-vx95-w3p5 was published for @jsonbored/gittensory-mcp (npm) Jul 9, 2026
homanp Credited to homanp
Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check Moderate
CVE-2026-50280 was published for craftcms/cms (Composer) Jul 2, 2026
larlarua Credited to larlarua
OpenClaw's browser act interactions could bypass private-network navigation checks Moderate
CVE-2026-53812 was published for openclaw (npm) Jul 2, 2026
cantinagen Credited to cantinagen and Ellahinator Ellahinator Ellahinator
OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn Moderate
GHSA-qh2f-99mv-mrcf was published for openclaw (npm) Jul 2, 2026
cantinagen Credited to cantinagen and Ellahinator Ellahinator Ellahinator
Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing Moderate
CVE-2026-53520 was published for github.com/nezhahq/nezha (Go) Jun 26, 2026
sondt99 Credited to sondt99
GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion Moderate
CVE-2026-48529 was published for github.com/github/github-mcp-server (Go) Jun 25, 2026
hewei-gikaku Credited to hewei-gikaku, matte1782, kerobbi, and JoannaaKL matte1782 matte1782
kerobbi kerobbi JoannaaKL JoannaaKL
motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint Moderate
CVE-2026-31978 was published for motioneye (pip) Jun 22, 2026
Neosprings Credited to Neosprings, blue-pho3nix, and MichaIng blue-pho3nix blue-pho3nix
MichaIng MichaIng
OpenCTI May Bypass Introspection Restriction Moderate
CVE-2024-37155 was published for pycti (pip) Jun 22, 2026
R-s0n Credited to R-s0n
Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion Moderate
CVE-2026-54015 was published for open-webui (pip) Jun 17, 2026
0xEr3n Credited to 0xEr3n, Classic298, and 5yu4n Classic298 Classic298
5yu4n 5yu4n
vvvvvvvvvvel Credited to vvvvvvvvvvel and Saku0512 Saku0512 Saku0512
Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks Moderate
CVE-2026-49411 was published for deno (Rust) Jun 16, 2026
sugarless1101 Credited to sugarless1101
n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint Moderate
GHSA-hv7x-3x78-gx53 was published for n8n (npm) Jun 16, 2026
34selen Credited to 34selen
vantage6 node has an Improper Access Control issue Moderate
CVE-2026-54533 was published for vantage6 (pip) Jun 5, 2026
NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints Moderate
CVE-2026-47279 was published for nocodb (npm) Jun 5, 2026
leduckhuong Credited to leduckhuong
Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*` Moderate
CVE-2026-47200 was published for @nuxt/nitro-server (npm) May 29, 2026
rmtsixq Credited to rmtsixq
@koa/router has an Access Control Bypass Moderate
CVE-2026-9495 was published for @koa/router (npm) May 26, 2026
Concrete CMS is vulnerable to unauthenticated page metadata disclosure Moderate
CVE-2026-8240 was published for concrete5/concrete5 (Composer) May 22, 2026
AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php` Moderate
CVE-2026-46337 was published for WWBN/AVideo (Composer) May 19, 2026
pr3ungdt Credited to pr3ungdt
Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass Moderate
CVE-2026-37979 was published for org.keycloak:keycloak-services (Maven) May 19, 2026
ProTip! Advisories are also available from the GraphQL API