Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34,555 advisories

Loading
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses Moderate
GHSA-hjwh-xvfw-qrwj was published for mcp-searxng (npm) Aug 19, 2026
NARKHEDE-VAIBHAV Credited to NARKHEDE-VAIBHAV
Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems High
CVE-2026-62673 was published for getgrav/grav (Composer) Aug 19, 2026
replit-svg Credited to replit-svg
Snipe-IT: Stored DOM XSS via table selected-count IDs Moderate
CVE-2026-61807 was published for snipe/snipe-it (Composer) Aug 19, 2026
Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET Moderate
CVE-2026-55703 was published for snipe/snipe-it (Composer) Aug 19, 2026
SakusenSec Credited to SakusenSec
Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover High
CVE-2026-55694 was published for snipe/snipe-it (Composer) Aug 19, 2026
Rajib-Mahmud Credited to Rajib-Mahmud
GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates High
CVE-2024-45747 was published for org.geoserver.web:gs-web-app (Maven) Aug 19, 2026
mbadanoiu Credited to mbadanoiu and sikeoka sikeoka sikeoka
SearXNG MCP Server: Additional hardened-mode SSRF bypasses Moderate
CVE-2026-54689 was published for mcp-searxng (npm) Aug 19, 2026
geo-chen Credited to geo-chen
XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing High
CVE-2026-53966 was published for org.xwiki.platform:xwiki-platform-livedata-livetable (Maven) Aug 19, 2026
tonghuaroot Credited to tonghuaroot
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes) High
CVE-2026-53964 was published for document-merge-service (pip) Aug 19, 2026
sofianeelhor Credited to sofianeelhor, c0rydoras, and tonghuaroot c0rydoras c0rydoras
tonghuaroot tonghuaroot
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted High
CVE-2026-53951 was published for copier (pip) Aug 19, 2026
seankohjs Credited to seankohjs and sisp sisp sisp
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS Moderate
CVE-2026-53941 was published for github.com/inspektor-gadget/inspektor-gadget (Go) Aug 19, 2026
alban Credited to alban, eiffel-fl, and mauriciovasquezbernal eiffel-fl eiffel-fl
mauriciovasquezbernal mauriciovasquezbernal
block_buffer: panic corrupts inline buffer position Moderate
GHSA-qwgh-2vcv-g2f7 was published for block_buffer (Rust) Aug 19, 2026
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools High
GHSA-rr55-jp92-8wp2 was published for claude-faf-mcp (npm) Aug 19, 2026
faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools High
GHSA-j4r7-8ph4-43g3 was published for faf-mcp (npm) Aug 19, 2026
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools High
GHSA-cc2g-gq8c-r332 was published for grok-faf-mcp (npm) Aug 19, 2026
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation Moderate
CVE-2026-55236 was published for langgraph-api (pip) Aug 19, 2026
OneThing4101 Credited to OneThing4101
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication Moderate
CVE-2026-55235 was published for langgraph-api (pip) Aug 19, 2026
BedheadProgrammer Credited to BedheadProgrammer
manus-use Credited to manus-use
moby/go-archive: Crafted tar archive can write outside the extraction directory High
CVE-2026-17106 was published for github.com/moby/go-archive (Go) Aug 18, 2026
thaJeztah Credited to thaJeztah, vvoland, and mickael-docker vvoland vvoland
mickael-docker mickael-docker
LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page High
GHSA-7gww-x7fh-jf9j was published for librenms/librenms (Composer) Aug 18, 2026
k1bana Credited to k1bana
LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users Moderate
GHSA-7cj5-v4pp-v632 was published for librenms/librenms (Composer) Aug 18, 2026
k1bana Credited to k1bana
ProTip! Advisories are also available from the GraphQL API