Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,574 advisories

Loading
fg0x0 Credited to fg0x0
MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials Moderate
CVE-2026-55854 was published for mariadb (npm) Aug 28, 2026
fg0x0 Credited to fg0x0
libreoffice-convert vulnerable to path traversal / arbitrary file write Moderate
CVE-2026-54732 was published for libreoffice-convert (npm) Aug 27, 2026
Santoshkumarpuppala Credited to Santoshkumarpuppala
n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter) Moderate
CVE-2026-54687 was published for n8n-nodes-sqlite3 (npm) Aug 27, 2026
dyingman1 Credited to dyingman1
@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint Moderate
CVE-2026-55605 was published for @arikusi/deepseek-mcp-server (npm) Aug 25, 2026
SungPilHan Credited to SungPilHan and arikusi arikusi arikusi
geo-chen Credited to geo-chen
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
gettext-converter: Prototype pollution in js2i18next() via crafted translation keys Moderate
CVE-2026-55451 was published for gettext-converter (npm) Aug 20, 2026
Dremig Credited to Dremig
next-video: Unauthenticated arbitrary file read via /api/video request handler Moderate
CVE-2026-54150 was published for next-video (npm) Aug 20, 2026
NocoBase backup restore schema name allows command injection Moderate
CVE-2026-55410 was published for @nocobase/plugin-backups (npm) Aug 20, 2026
sondt99 Credited to sondt99
Zwique Credited to Zwique
StarPlatinu Credited to StarPlatinu
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses Moderate
GHSA-hjwh-xvfw-qrwj was published for mcp-searxng (npm) Aug 19, 2026
NARKHEDE-VAIBHAV Credited to NARKHEDE-VAIBHAV
SearXNG MCP Server: Additional hardened-mode SSRF bypasses Moderate
CVE-2026-54689 was published for mcp-searxng (npm) Aug 19, 2026
geo-chen Credited to geo-chen
MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables Moderate
CVE-2026-63640 was published for magicmirror (npm) Aug 18, 2026
sondt99 Credited to sondt99
MagicMirror: ssrf calendar .js Moderate
CVE-2026-63643 was published for magicmirror (npm) Aug 18, 2026
gabrie0x6c Credited to gabrie0x6c
MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery Moderate
CVE-2026-63642 was published for magicmirror (npm) Aug 18, 2026
gabrie0x6c Credited to gabrie0x6c
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth Moderate
CVE-2026-69146 was published for mlflow (npm) Aug 17, 2026
geo-chen Credited to geo-chen
chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots Moderate
CVE-2026-53766 was published for chrome-devtools-mcp (npm) Aug 17, 2026
enable7997 Credited to enable7997
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling Moderate
GHSA-92hr-gmr6-h8cp was published for ep_etherpad-lite (npm) Aug 17, 2026
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints Moderate
CVE-2026-55156 was published for @ooples/token-optimizer-mcp (npm) Aug 14, 2026
232-323 Credited to 232-323
hashi-vault-js: Vault token and secret values exposed in thrown errors Moderate
CVE-2026-55102 was published for hashi-vault-js (npm) Aug 13, 2026
Sebasteuo Credited to Sebasteuo
ProTip! Advisories are also available from the GraphQL API