Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

762 advisories

Loading
arpitjain099 Credited to arpitjain099
plone.app.event vulnerable to denial of service via iCalendar import Critical
CVE-2026-55247 was published for plone.app.event (pip) Aug 28, 2026
plone.app.portlets vulnerable to denial of service via RSS feed portlet Critical
CVE-2026-55248 was published for plone.app.portlets (pip) Aug 28, 2026
senaite.core Vulnerable to Eval Injection and Missing Authorization Critical
CVE-2026-54569 was published for senaite.core (pip) Aug 26, 2026
snomi Credited to snomi and Volcore Volcore Volcore
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise) Critical
GHSA-93qj-5q5v-3c2h was published for pantheon-agents (pip) Aug 26, 2026
dokterbob Credited to dokterbob, qvipin, and ladderlogix qvipin qvipin
ladderlogix ladderlogix
fortress07 Credited to fortress07
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input Critical
CVE-2026-55546 was published for qwed-mcp (pip) Aug 25, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing Critical
CVE-2026-61539 was published for xinference (pip) Aug 21, 2026
XlabAITeam Credited to XlabAITeam, keenanwgn, and A7um keenanwgn keenanwgn
A7um A7um
surfio has an out-of-bounds read Critical
CVE-2026-55211 was published for surfio (pip) Aug 18, 2026
oddmunds Credited to oddmunds
oddmunds Credited to oddmunds
freeman-bb Credited to freeman-bb, y011d4, ibondarenko1, h1-mrz, and th3cyb3rc0p y011d4 y011d4
ibondarenko1 ibondarenko1 h1-mrz h1-mrz th3cyb3rc0p th3cyb3rc0p
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) Critical
CVE-2026-67429 was published for flyto-core (pip) Jul 30, 2026
kaimandalic Credited to kaimandalic
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding Critical
CVE-2026-64825 was published for homeassistant (pip) Jul 21, 2026
PercevalFox Credited to PercevalFox
patchmyday Credited to patchmyday
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests Critical
CVE-2026-61736 was published for lightrag-hku (pip) Jul 20, 2026
MaramHarsha Credited to MaramHarsha
Snowflake Connector for Python improperly verifies TLS hostnames Critical
CVE-2026-15925 was published for snowflake-connector-python (pip) Jul 16, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval Critical
CVE-2026-61667 was published for DIRAC (pip) Jul 13, 2026
sfayer Credited to sfayer
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input Critical
CVE-2026-45579 was published for DIRAC (pip) Jul 13, 2026
sfayer Credited to sfayer
mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials Critical
CVE-2026-61459 was published for mcp-server-kubernetes (pip) Jul 10, 2026
PercevalFox Credited to PercevalFox
YLChen-007 Credited to YLChen-007
ProTip! Advisories are also available from the GraphQL API