Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

15,233 advisories

Loading
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input Moderate
CVE-2026-45822 was published for decode-uri-component (npm) Aug 31, 2026
bnbdr Credited to bnbdr
@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking Moderate
CVE-2026-81888 was published for @hono/oauth-providers (npm) Aug 31, 2026
TarPeg007 Credited to TarPeg007
TYPO3 CMS - Unrestricted File Upload in Form Framework Moderate
CVE-2026-15305 was published for typo3/cms-form (Composer) Aug 31, 2026
brosua Credited to brosua
fg0x0 Credited to fg0x0
fg0x0 Credited to fg0x0
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output Moderate
CVE-2026-55859 was published for org.mariadb:r2dbc-mariadb (Maven) Aug 28, 2026
fg0x0 Credited to fg0x0
org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context Moderate
CVE-2026-55858 was published for org.mariadb.jdbc:mariadb-java-client (Maven) Aug 28, 2026
fg0x0 Credited to fg0x0
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials Moderate
CVE-2026-55857 was published for org.mariadb.jdbc:mariadb-java-client (Maven) Aug 28, 2026
fg0x0 Credited to fg0x0
MariaDB has cleartext password disclosure to a MITM on the initial-handshake Moderate
CVE-2026-55856 was published for org.mariadb.jdbc:mariadb-java-client (Maven) Aug 28, 2026
silverstripe/versioned has XSS in archive admin restore Moderate
CVE-2026-55779 was published for silverstripe/versioned (Composer) Aug 28, 2026
TA-MU-TA Credited to TA-MU-TA
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens Moderate
CVE-2026-55867 was published for org.graylog2:graylog2-server (Maven) Aug 28, 2026
michaelddickenson Credited to michaelddickenson and sreelim sreelim sreelim
MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials Moderate
CVE-2026-55854 was published for mariadb (npm) Aug 28, 2026
fg0x0 Credited to fg0x0
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset Moderate
CVE-2026-55678 was published for github.com/basekick-labs/arc (Go) Aug 28, 2026
sondt99 Credited to sondt99
EvidentObscurity Credited to EvidentObscurity, rugk, and elrido rugk rugk
elrido elrido
AIIR verification and policy gates could report success without enforcing the control (fail-open) Moderate
GHSA-73p9-6hrp-8qhr was published for aiir (pip) Aug 28, 2026
YHalo-wyh Credited to YHalo-wyh and nijel nijel nijel
p80n-sec Credited to p80n-sec
Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref Moderate
CVE-2026-55406 was published for buffa (Rust) Aug 28, 2026
Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields Moderate
CVE-2026-55425 was published for org.graylog2:graylog2-server (Maven) Aug 28, 2026
Evelynkaz Credited to Evelynkaz
Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint Moderate
CVE-2026-55515 was published for snipe/snipe-it (Composer) Aug 28, 2026
5h1kh4r Credited to 5h1kh4r
Snipe-IT has CSS Injection via `header_color` Setting Moderate
CVE-2026-55481 was published for snipe/snipe-it (Composer) Aug 28, 2026
ZeroXJacks Credited to ZeroXJacks
Snipe-IT has incorrect permission for legacy license checkin API Moderate
CVE-2026-55479 was published for snipe/snipe-it (Composer) Aug 28, 2026
Mitchell45 Credited to Mitchell45
Snipe-IT has missing object-level authorization in Kits API Moderate
CVE-2026-55478 was published for snipe/snipe-it (Composer) Aug 28, 2026
Mitchell45 Credited to Mitchell45
Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter Moderate
CVE-2026-55476 was published for snipe/snipe-it (Composer) Aug 28, 2026
iltosec Credited to iltosec and Mitchell45 Mitchell45 Mitchell45
ProTip! Advisories are also available from the GraphQL API