Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

113 advisories

Loading
mauriceng98 Credited to mauriceng98 and sean-kim05 sean-kim05 sean-kim05
Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in... Moderate Unreviewed
CVE-2026-86740 was published Sep 9, 2026
Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability Moderate
CVE-2026-62900 was published for Microsoft.Build.Tasks.Git (NuGet) Sep 8, 2026
Guzzle: URI fragments disclosed in redirect Referer headers Moderate
CVE-2026-67354 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths High
CVE-2026-53604 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations Moderate
CVE-2026-45737 was published for github.com/argoproj/argo-cd/v3 (Go) May 19, 2026
Gryph Agents Payload Filter Fails to Strip Tool Payload for Sensitive Content Moderate
CVE-2026-45046 was published for github.com/safedep/gryph (Go) May 11, 2026
dodge1218 Credited to dodge1218
FacturaScripts Vulnerable to Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/Download Moderate
CVE-2026-27892 was published for facturascripts/facturascripts (Composer) May 7, 2026
sudo0xksh Credited to sudo0xksh and iamsampathk iamsampathk iamsampathk
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction Critical
CVE-2026-42880 was published for github.com/argoproj/argo-cd/v3 (Go) May 7, 2026
hoang-prod Credited to hoang-prod
OpenBao's Namespace Deletion May Not Delete Data Properly Low
CVE-2026-42186 was published for github.com/openbao/openbao (Go) May 5, 2026
cipherboy Credited to cipherboy
ProTip! Advisories are also available from the GraphQL API