Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,601 advisories

Loading
Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name Critical
CVE-2026-55634 was published for pimcore/pimcore (Composer) Aug 28, 2026
Yanchon918s Credited to Yanchon918s
tonghuaroot Credited to tonghuaroot
plone.app.event vulnerable to denial of service via iCalendar import Critical
CVE-2026-55247 was published for plone.app.event (pip) Aug 28, 2026
plone.app.portlets vulnerable to denial of service via RSS feed portlet Critical
CVE-2026-55248 was published for plone.app.portlets (pip) Aug 28, 2026
Marnick39 Credited to Marnick39
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance) Critical
CVE-2026-55559 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
MarkLee131 Credited to MarkLee131 and manus-use manus-use manus-use
Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql` Critical
CVE-2026-55511 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
Yanchon918s Credited to Yanchon918s and manus-use manus-use manus-use
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints Critical
CVE-2026-55068 was published for github.com/free5gc/free5gc (Go) Aug 28, 2026
980448499-mm Credited to 980448499-mm
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) Critical
CVE-2026-54755 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
nickgs1337 Credited to nickgs1337
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) Critical
CVE-2026-54754 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
fbsobreira Credited to fbsobreira
senaite.core Vulnerable to Eval Injection and Missing Authorization Critical
CVE-2026-54569 was published for senaite.core (pip) Aug 26, 2026
snomi Credited to snomi and Volcore Volcore Volcore
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise) Critical
GHSA-93qj-5q5v-3c2h was published for pantheon-agents (pip) Aug 26, 2026
dokterbob Credited to dokterbob, qvipin, and ladderlogix qvipin qvipin
ladderlogix ladderlogix
AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching Critical
CVE-2026-49757 was published for ash_authentication (Erlang) Aug 25, 2026
jimsynz Credited to jimsynz, maennchen, and jarlah maennchen maennchen
jarlah jarlah
gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads Critical
CVE-2026-48853 was published for grpc (Erlang) Aug 25, 2026
PJUllrich Credited to PJUllrich, polvalente, and maennchen polvalente polvalente
maennchen maennchen
fortress07 Credited to fortress07
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input Critical
CVE-2026-55546 was published for qwed-mcp (pip) Aug 25, 2026
oscerd Credited to oscerd
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions Critical
CVE-2026-77415 was published for jsonata (npm) Aug 21, 2026
c0rydoras Credited to c0rydoras
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions Critical
CVE-2026-77414 was published for jsonata (npm) Aug 21, 2026
c0rydoras Credited to c0rydoras
JSONata: Arbitrary Code Execution via crafted JSONata expressions Critical
CVE-2026-77413 was published for jsonata (npm) Aug 21, 2026
peaktwilight Credited to peaktwilight and c0rydoras c0rydoras c0rydoras
ProTip! Advisories are also available from the GraphQL API