Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5,470 advisories

Loading
Keycloak vulnerable to authorization bypass via the Admin API Low
CVE-2026-2366 was published for @keycloak/keycloak-admin-client (Maven) Mar 12, 2026
Seafile Server has multiple stored XSS vulnerabilities Moderate
CVE-2026-30587 was published for @seafile/sdoc-editor (npm) Mar 25, 2026
mcp-handler has a tool response leak across concurrent client sessions ('Race Condition') High
GHSA-w2fm-25vw-vh7f was published for mcp-handler (npm) Apr 1, 2026
lodash vulnerable to Code Injection via `_.template` imports key names High
CVE-2026-4800 was published for lodash (npm) Apr 1, 2026
dolevmiz1 Credited to dolevmiz1, bugbunny-research, M0nd0R, UlisesGascon, falsyvalues, jonchurch, threalwinky, and jdalton bugbunny-research bugbunny-research
M0nd0R M0nd0R UlisesGascon UlisesGascon falsyvalues falsyvalues jonchurch jonchurch threalwinky threalwinky jdalton jdalton
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` Moderate
CVE-2026-2950 was published for lodash (npm) Apr 1, 2026
Haruna38 Credited to Haruna38, shpik-kr, maru1009, ott3r07, zolbooo, backuardo, falsyvalues, jonchurch, jdalton, and UlisesGascon shpik-kr shpik-kr
maru1009 maru1009 ott3r07 ott3r07 zolbooo zolbooo backuardo backuardo falsyvalues falsyvalues jonchurch jonchurch jdalton jdalton UlisesGascon UlisesGascon
NocoBase Has SQL Injection via template variable substitution in workflow SQL node High
CVE-2026-34825 was published for @nocobase/plugin-workflow-sql (npm) Apr 1, 2026
Parser Server's streaming file download bypasses afterFind file trigger authorization High
CVE-2026-34784 was published for parse-server (npm) Apr 1, 2026
offset Credited to offset and mtrezza mtrezza mtrezza
Haraka affected by DoS via `__proto__` email header High
CVE-2026-34752 was published for Haraka (npm) Apr 1, 2026
sebastianosrt Credited to sebastianosrt and msimerson msimerson msimerson
ngocnn97 Credited to ngocnn97
StableLib Ed25519 Signature Malleability via Missing S < L Check Moderate
GHSA-x3ff-w252-2g7j was published for @stablelib/ed25519 (npm) Apr 1, 2026
kodareef5 Credited to kodareef5
Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints Moderate
CVE-2026-34750 was published for @payloadcms/storage-azure (npm) Apr 1, 2026
SillyTavern: Incomplete IP validation in /api/search/visit allows SSRF via localhost and IPv6 Moderate
CVE-2026-34526 was published for sillytavern (npm) Apr 1, 2026
bulmax9797-sketch Credited to bulmax9797-sketch
maru1009 Credited to maru1009
SillyTavern: Path Traversal allows file existence oracle Moderate
CVE-2026-34523 was published for sillytavern (npm) Apr 1, 2026
kirakira-dev Credited to kirakira-dev
maru1009 Credited to maru1009
Payload has a CSRF Protection Bypass in Authentication Flow Moderate
CVE-2026-34749 was published for payload (npm) Apr 1, 2026
Payload has Authenticated SSRF via Upload Functionality High
CVE-2026-34746 was published for payload (npm) Apr 1, 2026
@payloadcms/next has Stored XSS in Admin Panel High
CVE-2026-34748 was published for @payloadcms/next (npm) Apr 1, 2026
Payload has an SQL Injection via Query Handling High
CVE-2026-34747 was published for payload (npm) Apr 1, 2026
hessandrew Credited to hessandrew and arkmarta arkmarta arkmarta
Claude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to Sibling Directories Moderate
CVE-2026-34451 was published for @anthropic-ai/sdk (npm) Apr 1, 2026
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController) Low
GHSA-53p3-c7vp-4mcc was published for action_text-trix (RubyGems) Mar 29, 2026
Payload has Unvalidated Input in Password Recovery Endpoints Critical
CVE-2026-34751 was published for @payloadcms/graphql (npm) Apr 1, 2026
wsk3r Credited to wsk3r
OpenClaw gateway exec allow-always over-trusts positional carrier executables High
GHSA-p4x4-2r7f-wjxg was published for openclaw (npm) Apr 1, 2026
nexrin Credited to nexrin
@tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions High
CVE-2026-34604 was published for @tinacms/graphql (npm) Apr 1, 2026
offset Credited to offset
@tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions High
CVE-2026-34603 was published for @tinacms/graphql (npm) Apr 1, 2026
offset Credited to offset
ProTip! Advisories are also available from the GraphQL API