Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,003 advisories

Loading
SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests High
CVE-2026-57443 was published for scbe-aethermoore (pip) Sep 25, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
mpp vulnerable to Gas Draining with low gas limit High
GHSA-vj8p-hp9x-gh47 was published for mpp (Erlang) Sep 25, 2026
kai-kka Credited to kai-kka
mpp vulnerable to Gas Draining with access list Moderate
GHSA-qpxh-ff8m-c62v was published for mpp (Erlang) Sep 25, 2026
kai-kka Credited to kai-kka
mpp vulnerable to Gas Draining with no limit High
GHSA-vv77-66rf-pm86 was published for mpp (Erlang) Sep 25, 2026
kai-kka Credited to kai-kka
CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers High
CVE-2026-100368 was published for AlastairLundy.CliInvoke.Specializations (NuGet) Sep 25, 2026
CliInvoke: Argument Injection in Extensibility Runner Factory High
CVE-2026-100369 was published for AlastairLundy.CliInvoke (NuGet) Sep 25, 2026
bulmax9797-sketch Credited to bulmax9797-sketch
uziii2208 Credited to uziii2208 and hoanggxyuuki hoanggxyuuki hoanggxyuuki
Containerd has image-pull DoS via crafted OCI index graph amplification Moderate
CVE-2026-53493 was published for github.com/containerd/containerd (Go) Sep 25, 2026
jake-ciolek Credited to jake-ciolek
FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider Critical
CVE-2026-92161 was published for fof/oauth (Composer) Sep 25, 2026
faran1512 Credited to faran1512
Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled High
CVE-2026-57440 was published for starcitizenwiki/embedvideo (Composer) Sep 25, 2026
code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute High
CVE-2026-61823 was published for code16/sharp (Composer) Sep 25, 2026
nova-aryan Credited to nova-aryan
code16/sharp has a stored XSS via data-html-content Sanitizer Bypass High
CVE-2026-61825 was published for code16/sharp (Composer) Sep 25, 2026
nova-aryan Credited to nova-aryan
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module Low
CVE-2026-57232 was published for contao/contao (Composer) Sep 24, 2026
Para213 Credited to Para213
social-auth-core has a Session Fixation issue Moderate
CVE-2026-57179 was published for social-auth-core (pip) Sep 24, 2026
mauriceng98 Credited to mauriceng98 and nijel nijel nijel
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing High
CVE-2026-57178 was published for social-auth-core (pip) Sep 24, 2026
lalalala5678 Credited to lalalala5678 and nijel nijel nijel
social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend Moderate
CVE-2026-57177 was published for social-auth-core (pip) Sep 24, 2026
mauriceng98 Credited to mauriceng98 and nijel nijel nijel
social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend Moderate
CVE-2026-57176 was published for social-auth-core (pip) Sep 24, 2026
mauriceng98 Credited to mauriceng98 and nijel nijel nijel
social-auth-core has an Improper Authentication issue Moderate
CVE-2026-57175 was published for social-auth-core (pip) Sep 24, 2026
mauriceng98 Credited to mauriceng98 and nijel nijel nijel
Ash: Private action arguments can be set by user input via string-keyed params and atomic changesets Moderate
CVE-2026-55736 was published for ash (Erlang) Sep 24, 2026
alfieV Credited to alfieV, zachdaniel, and maennchen zachdaniel zachdaniel
maennchen maennchen
Yanchon918s Credited to Yanchon918s
Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439) High
CVE-2026-57170 was published for compliance-trestle (pip) Sep 24, 2026
clzoom Credited to clzoom
Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint) High
CVE-2026-59723 was published for cline (npm) Sep 24, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
zbateson/mail-mime-parser has CRLF header injection via attachment filename High
CVE-2026-61815 was published for zbateson/mail-mime-parser (Composer) Sep 24, 2026
iliaal Credited to iliaal
ProTip! Advisories are also available from the GraphQL API