Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

12,566 advisories

Loading
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply High
CVE-2026-55764 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
nickgs1337 Credited to nickgs1337
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances High
CVE-2026-55761 was published for github.com/portainer/portainer (Go) Aug 28, 2026
um3b0shi Credited to um3b0shi
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits High
CVE-2026-55763 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
nickgs1337 Credited to nickgs1337 and fbsobreira fbsobreira fbsobreira
41Baloo Credited to 41Baloo
Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation High
CVE-2026-55212 was published for pimcore/studio-backend-bundle (Composer) Aug 28, 2026
dhairya7760 Credited to dhairya7760
byteoverride Credited to byteoverride
Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass High
CVE-2026-55207 was published for pimcore/studio-backend-bundle (Composer) Aug 28, 2026
byteoverride Credited to byteoverride
MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true` High
CVE-2026-55215 was published for mariadb (npm) Aug 28, 2026
Incus has a project restriction bypass in instance copy across projects High
CVE-2026-55622 was published for github.com/lxc/incus/v7/cmd/incusd (Go) Aug 28, 2026
antifob Credited to antifob and stgraber stgraber stgraber
Incus has a project restriction bypass for custom volume copy across projects High
CVE-2026-55621 was published for github.com/lxc/incus (Go) Aug 28, 2026
antifob Credited to antifob and stgraber stgraber stgraber
H3xV0rT3x Credited to H3xV0rT3x, nijel, and EndlssNightmare nijel nijel
EndlssNightmare EndlssNightmare
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching High
CVE-2026-55520 was published for Protego (pip) Aug 28, 2026
PowSyBl Core has Command Injection in LocalCommandExecutor-s High
CVE-2026-55673 was published for com.powsybl:powsybl-computation-local (Maven) Aug 28, 2026
Freakston Credited to Freakston
Spinnaker: Improper yaml processing on kustomize bake operations High
CVE-2026-55175 was published for io.spinnaker.rosco:rosco-manifests (Maven) Aug 28, 2026
thesecguy45 Credited to thesecguy45 and jasonmcintosh jasonmcintosh jasonmcintosh
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF High
CVE-2026-55641 was published for 9router (npm) Aug 28, 2026
EchoSkorJjj Credited to EchoSkorJjj
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass High
CVE-2026-55638 was published for 9router (npm) Aug 28, 2026
dinhvaren Credited to dinhvaren
phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers High
CVE-2026-55584 was published for phpsysinfo/phpsysinfo (Composer) Aug 28, 2026
mirackayikci Credited to mirackayikci
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL High
CVE-2026-55245 was published for github.com/maximhq/bifrost/core (Go) Aug 28, 2026
tonghuaroot Credited to tonghuaroot
black-shadow-007 Credited to black-shadow-007
WsgiDAV MySQL provider has a blind SQL injection High
CVE-2026-55509 was published for WsgiDAV (pip) Aug 28, 2026
Jvr2022 Credited to Jvr2022
Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update High
CVE-2026-55516 was published for snipe/snipe-it (Composer) Aug 28, 2026
5h1kh4r Credited to 5h1kh4r and builtbybrayden builtbybrayden builtbybrayden
Snipe-IT vulnerable to directory traversal in displaySig High
CVE-2026-55474 was published for snipe/snipe-it (Composer) Aug 28, 2026
Snipe-IT has an authorization bypass on bulk editing users High
CVE-2026-55460 was published for snipe/snipe-it (Composer) Aug 28, 2026
mamdouhmahfouz Credited to mamdouhmahfouz
Yamcs has Unauthenticated Directory Traversal High
CVE-2026-55552 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
suffs811 Credited to suffs811, AbdrrahimDahmani, and 0x4ndy AbdrrahimDahmani AbdrrahimDahmani
0x4ndy 0x4ndy
Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities High
CVE-2026-55521 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
lucquach Credited to lucquach
ProTip! Advisories are also available from the GraphQL API