GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
48
GitHub Actions
48
Go
3,391
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,614
Pub
13
RubyGems
1,013
Rust
1,205
Swift
51
Unreviewed advisories
All unreviewed
5,000+
5,470 advisories
Filter by severity
Keycloak vulnerable to authorization bypass via the Admin API
Low
CVE-2026-2366
was published
for
@keycloak/keycloak-admin-client
(Maven)
Mar 12, 2026
Seafile Server has multiple stored XSS vulnerabilities
Moderate
CVE-2026-30587
was published
for
@seafile/sdoc-editor
(npm)
Mar 25, 2026
mcp-handler has a tool response leak across concurrent client sessions ('Race Condition')
High
GHSA-w2fm-25vw-vh7f
was published
for
mcp-handler
(npm)
Apr 1, 2026
lodash vulnerable to Code Injection via `_.template` imports key names
High
CVE-2026-4800
was published
for
lodash
(npm)
Apr 1, 2026
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`
Moderate
CVE-2026-2950
was published
for
lodash
(npm)
Apr 1, 2026
NocoBase Has SQL Injection via template variable substitution in workflow SQL node
High
CVE-2026-34825
was published
for
@nocobase/plugin-workflow-sql
(npm)
Apr 1, 2026
Parser Server's streaming file download bypasses afterFind file trigger authorization
High
CVE-2026-34784
was published
for
parse-server
(npm)
Apr 1, 2026
Haraka affected by DoS via `__proto__` email header
High
CVE-2026-34752
was published
for
Haraka
(npm)
Apr 1, 2026
dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration
High
CVE-2026-34725
was published
for
dbgate-web
(npm)
Apr 1, 2026
StableLib Ed25519 Signature Malleability via Missing S < L Check
Moderate
GHSA-x3ff-w252-2g7j
was published
for
@stablelib/ed25519
(npm)
Apr 1, 2026
Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints
Moderate
CVE-2026-34750
was published
for
@payloadcms/storage-azure
(npm)
Apr 1, 2026
SillyTavern: Incomplete IP validation in /api/search/visit allows SSRF via localhost and IPv6
Moderate
CVE-2026-34526
was published
for
sillytavern
(npm)
Apr 1, 2026
SillyTavern: Path Traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user data root
High
CVE-2026-34524
was published
for
sillytavern
(npm)
Apr 1, 2026
SillyTavern: Path Traversal allows file existence oracle
Moderate
CVE-2026-34523
was published
for
sillytavern
(npm)
Apr 1, 2026
SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory
High
CVE-2026-34522
was published
for
sillytavern
(npm)
Apr 1, 2026
Payload has a CSRF Protection Bypass in Authentication Flow
Moderate
CVE-2026-34749
was published
for
payload
(npm)
Apr 1, 2026
Payload has Authenticated SSRF via Upload Functionality
High
CVE-2026-34746
was published
for
payload
(npm)
Apr 1, 2026
@payloadcms/next has Stored XSS in Admin Panel
High
CVE-2026-34748
was published
for
@payloadcms/next
(npm)
Apr 1, 2026
Payload has an SQL Injection via Query Handling
High
CVE-2026-34747
was published
for
payload
(npm)
Apr 1, 2026
Claude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to Sibling Directories
Moderate
CVE-2026-34451
was published
for
@anthropic-ai/sdk
(npm)
Apr 1, 2026
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)
Low
GHSA-53p3-c7vp-4mcc
was published
for
action_text-trix
(RubyGems)
Mar 29, 2026
Payload has Unvalidated Input in Password Recovery Endpoints
Critical
CVE-2026-34751
was published
for
@payloadcms/graphql
(npm)
Apr 1, 2026
OpenClaw gateway exec allow-always over-trusts positional carrier executables
High
GHSA-p4x4-2r7f-wjxg
was published
for
openclaw
(npm)
Apr 1, 2026
@tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions
High
CVE-2026-34604
was published
for
@tinacms/graphql
(npm)
Apr 1, 2026
@tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions
High
CVE-2026-34603
was published
for
@tinacms/graphql
(npm)
Apr 1, 2026
ProTip!
Advisories are also available from the
GraphQL API