Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,770 advisories

Loading
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console... Critical Unreviewed
CVE-2026-66013 was published Jul 25, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API Moderate
GHSA-86cx-wwf4-phq4 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
cns1rius Credited to cns1rius, xrgzs, jyxjjj, and sondt99 xrgzs xrgzs
jyxjjj jyxjjj sondt99 sondt99
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search Moderate
GHSA-p6ph-3jx2-3337 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
cns1rius Credited to cns1rius, jyxjjj, and xrgzs jyxjjj jyxjjj
xrgzs xrgzs
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own High
GHSA-rm67-g9ch-vxff was published for poweradmin/poweradmin (Composer) Jul 24, 2026
SaifSalah Credited to SaifSalah
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check Critical
GHSA-p279-2cqp-84jg was published for org.openidentityplatform.opendj:opendj-server-legacy (Maven) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
themudhaxk Credited to themudhaxk and Ardeey-code Ardeey-code Ardeey-code
DavidCarliez Credited to DavidCarliez and Classic298 Classic298 Classic298
waiveyk Credited to waiveyk and Classic298 Classic298 Classic298
@better-auth/stripe: cross-organization billing tampering in organization subscription actions High
GHSA-h3rm-78g3-j7cp was published for @better-auth/stripe (npm) Jul 24, 2026
@better-auth/scim: account takeover and stale access via SCIM provider-id collision Critical
GHSA-rjg6-39jm-rgg4 was published for @better-auth/scim (npm) Jul 24, 2026
Overseerr through 1.35.0 contains an authorization bypass through user-controlled key... Moderate Unreviewed
CVE-2026-65696 was published Jul 23, 2026
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions. Moderate Unreviewed
CVE-2026-65463 was published Jul 23, 2026
HO-9 Credited to HO-9
n8n: External Secrets Accessible via Workflow Expressions Outside Credentials Moderate
CVE-2026-59254 was published for n8n (npm) Jul 22, 2026
n8n: External Secrets Permission Bypass via Expression Parser Mismatch Moderate
CVE-2026-59259 was published for n8n (npm) Jul 22, 2026
YLChen-007 Credited to YLChen-007
ProTip! Advisories are also available from the GraphQL API