Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,539 advisories

Loading
carbon-apimgt does not properly restrict uploaded files Critical
CVE-2025-13590 was published for org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.admin.v1 (Maven) Feb 19, 2026
sealbenb Credited to sealbenb
Jenkins GitHub Plugin has an XSS vulnerability Critical
CVE-2026-42523 was published for com.coravy.hudson.plugins.github:github (Maven) Apr 29, 2026
sealbenb Credited to sealbenb
Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest Critical
CVE-2026-42027 was published for org.apache.opennlp:opennlp-tools (Maven) May 4, 2026
sealbenb Credited to sealbenb and maheshwarivijaykumar maheshwarivijaykumar maheshwarivijaykumar
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution Critical
CVE-2026-53476 was published for github.com/kubev2v/assisted-migration-agent (Go) Jun 10, 2026
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication Critical
CVE-2026-53475 was published for github.com/kubev2v/assisted-migration-agent (Go) Jun 10, 2026
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands Critical
CVE-2026-53474 was published for github.com/kubev2v/migration-planner (Go) Jun 10, 2026
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation Critical
CVE-2026-53471 was published for github.com/kubev2v/migration-planner (Go) Jun 10, 2026
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs Critical
CVE-2026-53470 was published for github.com/kubev2v/migration-planner (Go) Jun 10, 2026
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses Critical
CVE-2026-39830 was published for golang.org/x/crypto (Go) Jun 25, 2026
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default Critical
GHSA-r277-6w6q-xmqw was published for github.com/getkin/kin-openapi (Go) Jul 24, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API Critical
CVE-2026-53469 was published for github.com/kubev2v/migration-planner (Go) Jun 10, 2026
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding Critical
CVE-2026-64825 was published for homeassistant (pip) Jul 21, 2026
PercevalFox Credited to PercevalFox
Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE Critical
CVE-2026-53633 was published for @vitest/browser (npm) Jun 15, 2026
When Vitest UI server is listening, arbitrary file can be read and executed Critical
CVE-2026-47429 was published for vitest (npm) Jun 1, 2026
sapphi-red Credited to sapphi-red, qispark, joevin-slq-docto, koteswar-k, SaronGrave, and jason-anthropic qispark qispark
joevin-slq-docto joevin-slq-docto koteswar-k koteswar-k SaronGrave SaronGrave jason-anthropic jason-anthropic
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate Critical
CVE-2026-73653 was published for @vitest/browser (npm) Jul 21, 2026
manus-use Credited to manus-use
cruzryan Credited to cruzryan and cuauht cuauht cuauht
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check Critical
CVE-2026-73644 was published for org.openidentityplatform.opendj:opendj-server-legacy (Maven) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock Critical
CVE-2026-73567 was published for sm-crypto (npm) Jul 24, 2026
afldl Credited to afldl
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection Critical
CVE-2026-52830 was published for fast-mcp-telegram (pip) Jul 2, 2026
DavidCarliez Credited to DavidCarliez
Gogs has Path Traversal in organization name that results in RCE through Git hooks Critical
CVE-2026-52813 was published for gogs.io/gogs (Go) Jun 23, 2026
Aikido-Security Credited to Aikido-Security, JorianWoltjer, reindaelman, and grumpinout1 JorianWoltjer JorianWoltjer
reindaelman reindaelman grumpinout1 grumpinout1
marc-zollingkoffer-syzygy Credited to marc-zollingkoffer-syzygy
kakashi-kx Credited to kakashi-kx
Shescape: Shell injection via unescaped parentheses on Windows with CMD Critical
CVE-2026-73414 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials Critical
CVE-2026-61459 was published for mcp-server-kubernetes (pip) Jul 10, 2026
PercevalFox Credited to PercevalFox
Budibase has nonymous NoSQL operator injection via published-app query templates Critical
CVE-2026-54350 was published for @budibase/server (npm) Jun 23, 2026
kah-ja Credited to kah-ja
ProTip! Advisories are also available from the GraphQL API