Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

188 advisories

Loading
fg0x0 Credited to fg0x0
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output Moderate
CVE-2026-55859 was published for org.mariadb:r2dbc-mariadb (Maven) Aug 28, 2026
fg0x0 Credited to fg0x0
eml_parser has a URL extraction bypass via HTML entities in URLs Moderate
CVE-2026-55618 was published for eml_parser (pip) Aug 25, 2026
Sebasteuo Credited to Sebasteuo
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter Moderate
CVE-2026-70609 was published for electron (npm) Aug 5, 2026
hackerman70000 Credited to hackerman70000
CentreStack before 17.4 contains a session variable injection vulnerability that allows... Moderate Unreviewed
CVE-2026-54364 was published Jul 30, 2026
mathlive's Lack of Escaping of HTML allows for XSS Moderate
CVE-2026-54705 was published for mathlive (npm) Jul 29, 2026
CosmicCrusader23 Credited to CosmicCrusader23
Shescape: Home-directory disclosure in assignment context on Unix with Dash Moderate
CVE-2026-73411 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797 Moderate
GHSA-hc76-7mpc-qjqh was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
yorukot Credited to yorukot
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility Moderate
CVE-2026-59895 was published for hono (npm) Jul 21, 2026
a-tt-om Credited to a-tt-om and teebow1e teebow1e teebow1e
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability Moderate
CVE-2026-50659 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Jul 20, 2026
Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization Moderate
CVE-2026-49844 was published for org.apache.logging.log4j:log4j-api (Maven) Jul 11, 2026
ppkarwasz Credited to ppkarwasz, ashwani945, and Lueton ashwani945 ashwani945
Lueton Lueton
YesWiki has stored XSS in Bazar form-field templates via unescaped field.label / field.hint (|raw('html')) Moderate
CVE-2026-52772 was published for yeswiki/yeswiki (Composer) Jul 9, 2026
offset Credited to offset
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection) Moderate
CVE-2026-35366 was published for uu_printenv (Rust) Jul 6, 2026
justhtml: to_markdown() code-span blank-line breakout enables XSS Moderate
GHSA-jf6w-2mvx-633j was published for justhtml (pip) Jun 25, 2026
seankohjs Credited to seankohjs and yueyueL yueyueL yueyueL
ProTip! Advisories are also available from the GraphQL API