Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

12,530 advisories

Loading
Kirby: File upload permissions are not checked during processing of chunk data High
CVE-2026-71415 was published for getkirby/cms (Composer) Aug 31, 2026
alcls01111 Credited to alcls01111
Pig-Tail Credited to Pig-Tail
Socket.IO: Engine.IO WebTransport SID DoS High
CVE-2026-59724 was published for engine.io (npm) Aug 31, 2026
ni8walk3r Credited to ni8walk3r
elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback High
CVE-2026-81889 was published for studio-42/elfinder (Composer) Aug 31, 2026
Marco198333 Credited to Marco198333
RestrictedPython guard hooks can be shadowed via positional-only arguments High
CVE-2026-55830 was published for RestrictedPython (pip) Aug 28, 2026
Neroli-realy Credited to Neroli-realy, dataflake, and taisehub dataflake dataflake
taisehub taisehub
Snipe-IT has an Improper Privilege Management issue High
CVE-2026-55843 was published for snipe/snipe-it (Composer) Aug 28, 2026
mattimustang Credited to mattimustang
MapFish Print has XXE that allows reading arbitrary files of certain types High
CVE-2026-55848 was published for org.mapfish.print:print-lib (Maven) Aug 28, 2026
zneek Credited to zneek
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI High
CVE-2026-55784 was published for github.com/free5gc/ausf (Go) Aug 28, 2026
jaimealruiz Credited to jaimealruiz and jav1er8 jav1er8 jav1er8
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read High
CVE-2026-55874 was published for github.com/seaweedfs/seaweedfs (Go) Aug 28, 2026
47Cid Credited to 47Cid
Fortigate syslog message parser can be exploited to modify or delete fields from the original message High
CVE-2026-55841 was published for org.graylog2:graylog2-server (Maven) Aug 28, 2026
joseluisgonzalezca Credited to joseluisgonzalezca and borjam borjam borjam
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply High
CVE-2026-55764 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
nickgs1337 Credited to nickgs1337
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances High
CVE-2026-55761 was published for github.com/portainer/portainer (Go) Aug 28, 2026
um3b0shi Credited to um3b0shi
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits High
CVE-2026-55763 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
nickgs1337 Credited to nickgs1337 and fbsobreira fbsobreira fbsobreira
41Baloo Credited to 41Baloo
Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation High
CVE-2026-55212 was published for pimcore/studio-backend-bundle (Composer) Aug 28, 2026
dhairya7760 Credited to dhairya7760
byteoverride Credited to byteoverride
Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass High
CVE-2026-55207 was published for pimcore/studio-backend-bundle (Composer) Aug 28, 2026
byteoverride Credited to byteoverride
MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true` High
CVE-2026-55215 was published for mariadb (npm) Aug 28, 2026
Incus has a project restriction bypass in instance copy across projects High
CVE-2026-55622 was published for github.com/lxc/incus/v7/cmd/incusd (Go) Aug 28, 2026
antifob Credited to antifob and stgraber stgraber stgraber
Incus has a project restriction bypass for custom volume copy across projects High
CVE-2026-55621 was published for github.com/lxc/incus (Go) Aug 28, 2026
antifob Credited to antifob and stgraber stgraber stgraber
H3xV0rT3x Credited to H3xV0rT3x, nijel, and EndlssNightmare nijel nijel
EndlssNightmare EndlssNightmare
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching High
CVE-2026-55520 was published for Protego (pip) Aug 28, 2026
PowSyBl Core has Command Injection in LocalCommandExecutor-s High
CVE-2026-55673 was published for com.powsybl:powsybl-computation-local (Maven) Aug 28, 2026
Freakston Credited to Freakston
Spinnaker: Improper yaml processing on kustomize bake operations High
CVE-2026-55175 was published for io.spinnaker.rosco:rosco-manifests (Maven) Aug 28, 2026
thesecguy45 Credited to thesecguy45 and jasonmcintosh jasonmcintosh jasonmcintosh
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF High
CVE-2026-55641 was published for 9router (npm) Aug 28, 2026
EchoSkorJjj Credited to EchoSkorJjj
ProTip! Advisories are also available from the GraphQL API