GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
386 advisories
Filter by severity
Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout
Moderate
CVE-2026-107804
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Oct 9, 2026
Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not validate the `Host` header
Moderate
CVE-2026-107292
was published
for
pydantic-ai
(pip)
Oct 8, 2026
Next.js has information disclosure in App Router metadata image routes via dynamicParams bypass
Moderate
CVE-2026-94485
was published
for
next
(npm)
Oct 7, 2026
Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that...
Moderate
Unreviewed
CVE-2026-105396
was published
Oct 5, 2026
A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery ...
Moderate
Unreviewed
CVE-2026-102588
was published
Sep 30, 2026
Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in...
Moderate
Unreviewed
CVE-2026-100821
was published
Sep 29, 2026
An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker...
Moderate
Unreviewed
CVE-2026-18825
was published
Sep 28, 2026
Fabasoft Folio Client before 2026, a locally installed component that communicates with the...
Moderate
Unreviewed
CVE-2026-97155
was published
Sep 24, 2026
Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local...
Moderate
Unreviewed
CVE-2026-94111
was published
Sep 20, 2026
Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools
Moderate
CVE-2026-77339
was published
for
github.com/f1bonacc1/process-compose
(Go)
Sep 18, 2026
Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not...
Moderate
Unreviewed
CVE-2026-75025
was published
Sep 16, 2026
A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof,...
Moderate
Unreviewed
CVE-2026-77119
was published
Sep 16, 2026
Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156...
Moderate
Unreviewed
CVE-2026-92068
was published
Sep 15, 2026
DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the...
Moderate
Unreviewed
CVE-2026-91201
was published
Sep 15, 2026
An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280,...
Moderate
Unreviewed
CVE-2026-23792
was published
Sep 14, 2026
Origin validation error in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote...
Moderate
Unreviewed
CVE-2026-87563
was published
Sep 9, 2026
Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose...
Moderate
Unreviewed
CVE-2026-69559
was published
Sep 8, 2026
Origin validation error in .NET allows an unauthorized attacker to disclose information over a...
Moderate
Unreviewed
CVE-2026-58649
was published
Sep 8, 2026
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155 and...
Moderate
Unreviewed
CVE-2026-84137
was published
Sep 1, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2026-70309
was published
Aug 28, 2026
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
Moderate
CVE-2026-55529
was published
for
PraisonAI
(pip)
Aug 25, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
Moderate
CVE-2026-67448
was published
for
github.com/axllent/mailpit
(Go)
Aug 20, 2026
Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in...
Moderate
Unreviewed
CVE-2026-74974
was published
Aug 18, 2026
Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in...
Moderate
Unreviewed
CVE-2026-74968
was published
Aug 18, 2026
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154 and...
Moderate
Unreviewed
CVE-2026-74970
was published
Aug 18, 2026
ProTip!
Advisories are also available from the
GraphQL API