Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

739 advisories

Loading
Vikunja: OIDC email-fallback account linking ignores email_verified, enabling local-account takeover High
CVE-2026-62367 was published for code.vikunja.io/api (Go) Oct 9, 2026
maskop9 Credited to maskop9 and evilgensec evilgensec evilgensec
pyLoad: Rate-Limit Bypass and Audit-Log Spoofing via Trusted Client-Controlled `X-Forwarded-For` Header Moderate
GHSA-9q47-3cm2-2rp8 was published for pyload-ng (pip) Oct 9, 2026
nirtem Credited to nirtem
Payload authentication token field handling issue Critical
CVE-2026-105863 was published for payload (npm) Oct 7, 2026
Zerotistic Credited to Zerotistic
mppx-condition-gate: Free-access path grants on a self-declared wallet without proving control High
CVE-2026-104891 was published for @insumermodel/mppx-condition-gate (npm) Oct 7, 2026
chenshj73 Credited to chenshj73
Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write High
CVE-2026-105741 was published for langflow (pip) Oct 7, 2026
erichare Credited to erichare and andifilhohub andifilhohub andifilhohub
dinhvaren Credited to dinhvaren
Unauthenticated Bypass Vulnerability in Login Lockdown <= 2.17 versions. Moderate Unreviewed
CVE-2026-97308 was published Oct 6, 2026
Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions. Moderate Unreviewed
CVE-2026-39772 was published Oct 6, 2026
Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions. Moderate Unreviewed
CVE-2026-105057 was published Oct 6, 2026
proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet Critical
CVE-2026-90711 was published for proxy-addr (npm) Oct 5, 2026
kagebunsher Credited to kagebunsher, UlisesGascon, and kustundag UlisesGascon UlisesGascon
kustundag kustundag
ProTip! Advisories are also available from the GraphQL API