Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34,076 advisories

Loading
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files High
CVE-2026-54910 was published for github.com/gtsteffaniak/filebrowser/backend (Go) Jul 31, 2026
je-lv Credited to je-lv
guard-livereload has a directory traversal vulnerability Moderate
CVE-2016-1000305 was published for guard-livereload (RubyGems) Jul 31, 2026
gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode Moderate
CVE-2026-54785 was published for gemini-bridge (pip) Jul 31, 2026
mcfly-zzh Credited to mcfly-zzh
lukegranto23 Credited to lukegranto23
core-geonetwork has an Open Redirect Bypass Moderate
CVE-2026-53573 was published for org.geonetwork-opensource:geonetwork (Maven) Jul 31, 2026
Fushuling Credited to Fushuling, RacerZ-fighting, and juanluisrp RacerZ-fighting RacerZ-fighting
juanluisrp juanluisrp
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message Moderate
CVE-2026-54908 was published for github.com/pion/dtls/v3 (Go) Jul 31, 2026
Sean-Der Credited to Sean-Der and kajaaz kajaaz kajaaz
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute Moderate
CVE-2026-54909 was published for github.com/pion/stun (Go) Jul 31, 2026
kajaaz Credited to kajaaz and Sean-Der Sean-Der Sean-Der
sigstore-go fails to check signature timestamps against a signing key's validity period Low
CVE-2026-54787 was published for github.com/sigstore/sigstore-go (Go) Jul 31, 2026
tnytown Credited to tnytown
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag High
CVE-2026-53608 was published for @apostrophecms/seo (npm) Jul 31, 2026
H3xV0rT3x Credited to H3xV0rT3x
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header Low
CVE-2026-53607 was published for apostrophe (npm) Jul 31, 2026
EchoSkorJjj Credited to EchoSkorJjj
H3xV0rT3x Credited to H3xV0rT3x
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure Moderate
CVE-2026-53551 was published for github.com/free5gc/ausf (Go) Jul 31, 2026
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit Moderate
GHSA-3whf-vgf2-9w6g was published for zaino-state (Rust) Jul 31, 2026
ouicate Credited to ouicate
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE Critical
CVE-2026-52887 was published for @nocobase/plugin-notification-in-app-message (npm) Jul 31, 2026
kah-ja Credited to kah-ja
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow Moderate
CVE-2026-53466 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 31, 2026
Bin-infinite Credited to Bin-infinite
Savon::Model evaluates WSDL operation names as Ruby source High
CVE-2026-53510 was published for savon (RubyGems) Jul 31, 2026
connorshea Credited to connorshea
CrownKingClown Credited to CrownKingClown
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier High
CVE-2026-58263 was published for jodit (npm) Jul 31, 2026
koyokr Credited to koyokr
Jodit has prototype pollution via Jodit.configure() / ConfigMerge Moderate
CVE-2026-54756 was published for jodit (npm) Jul 31, 2026
koyokr Credited to koyokr
Thumbor has path traversal via post-validation URL decoding bypass in file_loader High
CVE-2026-53502 was published for thumbor (pip) Jul 31, 2026
q1uf3ng Credited to q1uf3ng and 0xHunSec 0xHunSec 0xHunSec
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS High
CVE-2026-53505 was published for thumbor (pip) Jul 31, 2026
m01e-40x Credited to m01e-40x
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter High
CVE-2026-53504 was published for thumbor (pip) Jul 31, 2026
geraldino2 Credited to geraldino2
ProTip! Advisories are also available from the GraphQL API