Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

52 advisories

Loading
[This CNA information record relates to multiple CVEs; the text explains which aspects... Critical Unreviewed
CVE-2026-23562 was published Jul 9, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects... Critical Unreviewed
CVE-2026-42486 was published Jul 9, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects... Critical Unreviewed
CVE-2026-23559 was published Jul 9, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects... Critical Unreviewed
CVE-2026-23560 was published Jul 9, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects... Critical Unreviewed
CVE-2026-23561 was published Jul 9, 2026
Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation Critical
CVE-2026-50566 was published for github.com/fission/fission (Go) Jun 30, 2026
HiyokoSauna37 Credited to HiyokoSauna37 and sanketsudake sanketsudake sanketsudake
Execution with unnecessary privileges in Microsoft Dynamics 365 (on-premises) allows an... Critical Unreviewed
CVE-2026-42833 was published May 12, 2026
CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE Critical
CVE-2026-44477 was published for github.com/cloudnative-pg/cloudnative-pg (Go) May 11, 2026
mdisec Credited to mdisec
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool Critical
GHSA-2wvh-87g2-89hr was published for openc3 (RubyGems) Apr 23, 2026
suffs811 Credited to suffs811
An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0.... Critical Unreviewed
CVE-2026-34877 was published Apr 2, 2026
A vulnerability has been identified in the ServiceNow AI Platform that could enable an... Critical Unreviewed
CVE-2025-12420 was published Jan 13, 2026
Neuron MySQLWriteTool allows arbitrary/destructive SQL when exposed to untrusted prompts (agent “footgun”) Critical
CVE-2025-67510 was published for neuron-core/neuron-ai (Composer) Dec 9, 2025
siewer Credited to siewer
ProTip! Advisories are also available from the GraphQL API