GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,931
Maven
5,000+
npm
5,000+
NuGet
969
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,382
Swift
56
Unreviewed advisories
All unreviewed
5,000+
2,205 advisories
Filter by severity
Parse Server's GraphQL "Did you mean ...?" validation suggestions disclose schema to unauthenticated callers
Moderate
CVE-2026-47248
was published
for
parse-server
(npm)
May 29, 2026
NodeVM observability builtins leak host process and HTTP request data
Moderate
CVE-2026-47141
was published
for
vm2
(npm)
May 29, 2026
ExifReader is vulnerable to denial of service via unbounded decompression of image metadata
Moderate
CVE-2026-8814
was published
for
exifreader
(npm)
May 29, 2026
Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`
Moderate
CVE-2026-47200
was published
for
@nuxt/nitro-server
(npm)
May 29, 2026
axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
Moderate
CVE-2026-44490
was published
for
axios
(npm)
May 29, 2026
FUXA provides guest and invalid-token access to protected read APIs in secure mode
Moderate
CVE-2026-47718
was published
for
fuxa-server
(npm)
May 28, 2026
Shamefile has an arbitrary file read via shamefile.yaml in shame next
Moderate
CVE-2026-47144
was published
for
shamefile
(npm)
May 28, 2026
@hapi/wreck leaks sensitive `Proxy-Authorization` header across cross-hostname redirects
Moderate
CVE-2026-44979
was published
for
@hapi/wreck
(npm)
May 27, 2026
LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`
Moderate
CVE-2026-44646
was published
for
liquidjs
(npm)
May 27, 2026
LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body
Moderate
CVE-2026-44645
was published
for
liquidjs
(npm)
May 27, 2026
LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS
Moderate
CVE-2026-44644
was published
for
liquidjs
(npm)
May 27, 2026
CryptPad has a Sanitizer Bypass in Diffmarked.js that Allows Arbitrary HTML Injection and Potential XSS
Moderate
CVE-2026-26028
was published
for
cryptpad
(npm)
May 26, 2026
Typebot.io has stored XSS via `javascript`: URI in text bubble links — bot author executes JS on visitors' browsers
Moderate
CVE-2026-39964
was published
for
@typebot.io/js
(npm)
May 26, 2026
qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set
Moderate
CVE-2026-8723
was published
for
qs
(npm)
May 22, 2026
@hulumi/baseline: CloudTrail selector tampering events were not fully detected
Moderate
GHSA-gfp8-mp24-5vxg
was published
for
@hulumi/baseline
(npm)
May 21, 2026
NocoDB: Shared-base link access can invite arbitrary users as persistent base members
Moderate
CVE-2026-46552
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion
Moderate
CVE-2026-46551
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: Refresh Token Cookie Set Without `secure` and `sameSite` Flags
Moderate
CVE-2026-46550
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams)
Moderate
CVE-2026-46548
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL
Moderate
CVE-2026-46547
was published
for
nocodb
(npm)
May 21, 2026
@sveltejs/kit: `query.batch` cross-talk
Moderate
GHSA-hgv7-v322-mmgr
was published
for
@sveltejs/kit
(npm)
May 21, 2026
Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows
Moderate
GHSA-c2c9-mfw7-p8hw
was published
for
flowise
(npm)
May 20, 2026
Flowise: Mass Assignment in PUT /api/v1/user Allows Authenticated Users to Override Password Hash and Bypass Password Change Verification
Moderate
GHSA-59fh-9f3p-7m39
was published
for
flowise
(npm)
May 20, 2026
Flowise: Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse from any webpage
Moderate
GHSA-m837-xvxr-vqwg
was published
for
flowise
(npm)
May 20, 2026
HAX CMS: Denial of Service using Malicious Import Request
Moderate
CVE-2026-46357
was published
for
@haxtheweb/haxcms-nodejs
(npm)
May 19, 2026
ProTip!
Advisories are also available from the
GraphQL API