GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
2,574 advisories
Filter by severity
MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets
Moderate
CVE-2026-55855
was published
for
mariadb
(npm)
Aug 28, 2026
MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
Moderate
CVE-2026-55854
was published
for
mariadb
(npm)
Aug 28, 2026
libreoffice-convert vulnerable to path traversal / arbitrary file write
Moderate
CVE-2026-54732
was published
for
libreoffice-convert
(npm)
Aug 27, 2026
n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)
Moderate
CVE-2026-54687
was published
for
n8n-nodes-sqlite3
(npm)
Aug 27, 2026
@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint
Moderate
CVE-2026-55605
was published
for
@arikusi/deepseek-mcp-server
(npm)
Aug 25, 2026
mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)
Moderate
CVE-2026-55663
was published
for
mediasoup
(npm)
Aug 25, 2026
Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username
Moderate
CVE-2026-63466
was published
for
unleash-server
(npm)
Aug 21, 2026
Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers
Moderate
CVE-2026-63004
was published
for
unleash-server
(npm)
Aug 21, 2026
gettext-converter: Prototype pollution in js2i18next() via crafted translation keys
Moderate
CVE-2026-55451
was published
for
gettext-converter
(npm)
Aug 20, 2026
next-video: Unauthenticated arbitrary file read via /api/video request handler
Moderate
CVE-2026-54150
was published
for
next-video
(npm)
Aug 20, 2026
NocoBase backup restore schema name allows command injection
Moderate
CVE-2026-55410
was published
for
@nocobase/plugin-backups
(npm)
Aug 20, 2026
Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root
Moderate
CVE-2026-63123
was published
for
@tinacms/cli
(npm)
Aug 19, 2026
Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)
Moderate
CVE-2026-59992
was published
for
next-tinacms-azure
(npm)
Aug 19, 2026
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
Moderate
GHSA-hjwh-xvfw-qrwj
was published
for
mcp-searxng
(npm)
Aug 19, 2026
SearXNG MCP Server: Additional hardened-mode SSRF bypasses
Moderate
CVE-2026-54689
was published
for
mcp-searxng
(npm)
Aug 19, 2026
SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
Moderate
CVE-2026-54688
was published
for
mcp-searxng
(npm)
Aug 19, 2026
MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables
Moderate
CVE-2026-63640
was published
for
magicmirror
(npm)
Aug 18, 2026
MagicMirror: ssrf calendar .js
Moderate
CVE-2026-63643
was published
for
magicmirror
(npm)
Aug 18, 2026
MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery
Moderate
CVE-2026-63642
was published
for
magicmirror
(npm)
Aug 18, 2026
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
Moderate
CVE-2026-69146
was published
for
mlflow
(npm)
Aug 17, 2026
chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots
Moderate
CVE-2026-53766
was published
for
chrome-devtools-mcp
(npm)
Aug 17, 2026
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling
Moderate
GHSA-92hr-gmr6-h8cp
was published
for
ep_etherpad-lite
(npm)
Aug 17, 2026
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
Moderate
CVE-2026-55156
was published
for
@ooples/token-optimizer-mcp
(npm)
Aug 14, 2026
hashi-vault-js: Vault token and secret values exposed in thrown errors
Moderate
CVE-2026-55102
was published
for
hashi-vault-js
(npm)
Aug 13, 2026
ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
Moderate
CVE-2026-55088
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
ProTip!
Advisories are also available from the
GraphQL API