Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34,792 advisories

Loading
OpenSTAManager has HTML Injection in modules/utenti/edit.php Low
CVE-2026-44701 was published for devcode-it/openstamanager (Composer) Aug 26, 2026
ilmercu Credited to ilmercu
LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates High
GHSA-7w8c-qgxg-m7jx was published for librenms/librenms (Composer) Aug 26, 2026
TristanInSec Credited to TristanInSec
asyncssh has SCP Path Traversal to Arbitrary File Write High
CVE-2026-54591 was published for asyncssh (pip) Aug 26, 2026
Jaden-Furtado Credited to Jaden-Furtado and JadenFurtado JadenFurtado JadenFurtado
cakephp/debug_kit: MailPreview contains unsafe reflection Moderate
CVE-2026-54614 was published for cakephp/debug_kit (Composer) Aug 26, 2026
edorian Credited to edorian
senaite.core Vulnerable to Eval Injection and Missing Authorization Critical
CVE-2026-54569 was published for senaite.core (pip) Aug 26, 2026
snomi Credited to snomi and Volcore Volcore Volcore
SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed High
CVE-2026-54606 was published for suneditor (npm) Aug 26, 2026
Adyej999 Credited to Adyej999
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root High
CVE-2026-54563 was published for github.com/cloudreve/Cloudreve/v3 (Go) Aug 26, 2026
riodrwn Credited to riodrwn
dizconnectz Credited to dizconnectz and nemesifier nemesifier nemesifier
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise) Critical
GHSA-93qj-5q5v-3c2h was published for pantheon-agents (pip) Aug 26, 2026
AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore Moderate
CVE-2026-55688 was published for org.asynchttpclient:async-http-client (Maven) Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation Low
CVE-2026-54786 was published for wasmtime-wasi (Rust) Aug 26, 2026
alexcrichton Credited to alexcrichton
@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys High
CVE-2026-54511 was published for @logtape/syslog (npm) Aug 26, 2026
IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries High
CVE-2026-54550 was published for org.codehaus.izpack:izpack-installer (Maven) Aug 26, 2026
sectroyer Credited to sectroyer
kas Persistently Disables SSH Host Key Checking Low
CVE-2026-54548 was published for kas (pip) Aug 26, 2026
shubtheone Credited to shubtheone
muslimbek-0x Credited to muslimbek-0x
http4s has HTTP/2 Denial of Service with Ember Backend High
CVE-2026-54556 was published for org.http4s:http4s-ember-core_2.12 (Maven) Aug 26, 2026
reardonj Credited to reardonj and rossabaker rossabaker rossabaker
Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url` High
CVE-2026-54356 was published for @budibase/server (npm) Aug 26, 2026
KovachVL Credited to KovachVL
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login Moderate
CVE-2026-54338 was published for jupyterhub (pip) Aug 25, 2026
mauriceng98 Credited to mauriceng98, Zyy0530, Str1ckl4nd, and 7thParkk Zyy0530 Zyy0530
Str1ckl4nd Str1ckl4nd 7thParkk 7thParkk
icalendar has Algorithmic Complexity in Equality High
CVE-2026-55099 was published for icalendar (pip) Aug 25, 2026
tidusec Credited to tidusec
dokterbob Credited to dokterbob, qvipin, and ladderlogix qvipin qvipin
ladderlogix ladderlogix
dokterbob Credited to dokterbob, qvipin, and ladderlogix qvipin qvipin
ladderlogix ladderlogix
@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint Moderate
CVE-2026-55605 was published for @arikusi/deepseek-mcp-server (npm) Aug 25, 2026
SungPilHan Credited to SungPilHan and arikusi arikusi arikusi
@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key High
CVE-2026-55604 was published for @arikusi/deepseek-mcp-server (npm) Aug 25, 2026
232-323 Credited to 232-323 and arikusi arikusi arikusi
ProTip! Advisories are also available from the GraphQL API