GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
7,257 advisories
Filter by severity
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
Low
CVE-2026-70598
was published
for
electron
(npm)
Aug 5, 2026
Electron: Parent process code-sign check is spoofable
Moderate
CVE-2026-70597
was published
for
electron
(npm)
Aug 5, 2026
Ghost Content API filter bypass reveals private fields
Moderate
CVE-2026-53949
was published
for
ghost
(npm)
Aug 5, 2026
Ghost: Cross-Site Scripting in Feature Image Captions
Moderate
CVE-2026-70596
was published
for
ghost
(npm)
Aug 5, 2026
Ghost: Server-Side Request Forgery Mitigation Issue
Moderate
CVE-2026-70595
was published
for
ghost
(npm)
Aug 5, 2026
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
Moderate
CVE-2026-59817
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Member existence leak via magic link sign-in response
Moderate
CVE-2026-53947
was published
for
ghost
(npm)
Aug 4, 2026
XSS in Ghost's ActivityPub client
High
CVE-2026-53950
was published
for
@tryghost/activitypub
(npm)
Aug 4, 2026
Ghost: Session Fixation in Ghost Admin
Moderate
CVE-2026-70594
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Theme Upload Path Traversal
Moderate
CVE-2026-70593
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Database Backup Path Traversal
Moderate
CVE-2026-70592
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Server-Side Request Forgery in Image Fetching
Moderate
CVE-2026-70591
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Blind Password Hash Disclosure in Ghost Admin API
Moderate
CVE-2026-70590
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Mobiledoc image-size fetch SSRF
Moderate
CVE-2026-53946
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Server-side request forgery via DNS rebinding in external request handling
Moderate
CVE-2026-53945
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Private IP filtering bypass to make server-side requests to internal services
Moderate
CVE-2026-53944
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Archived Offers can be Redeemed
Moderate
CVE-2026-70589
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: File Upload Content-Type Spoofing
Moderate
CVE-2026-53948
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Cross-Site Scripting in Universal Import
Moderate
CVE-2026-70588
was published
for
ghost
(npm)
Aug 4, 2026
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
Critical
CVE-2026-70478
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Critical
CVE-2026-70477
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
High
CVE-2026-70476
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
Moderate
GHSA-8gj2-2cvc-6xx7
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Missing Authorization on Execution Update Endpoint
High
CVE-2026-70475
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
High
CVE-2026-70474
was published
for
flowise
(npm)
Aug 4, 2026
ProTip!
Advisories are also available from the
GraphQL API