close
Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34,387 advisories

Loading
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv) High
CVE-2026-55074 was published for ansible-jailexec (pip) Aug 12, 2026
manus-use Credited to manus-use
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing High
GHSA-jwjp-4649-v8jp was published for SIPSorcery (NuGet) Aug 12, 2026
manus-use Credited to manus-use
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install` High
CVE-2026-55071 was published for stata-mcp (pip) Aug 12, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access High
CVE-2026-54917 was published for github.com/seaweedfs/seaweedfs (Go) Aug 12, 2026
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0 High
CVE-2026-52776 was published for compliance-trestle (pip) Aug 12, 2026
tonghuaroot Credited to tonghuaroot
Nadav0077 Credited to Nadav0077 and igorpyan igorpyan igorpyan
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint Moderate
CVE-2026-48786 was published for github.com/fleetdm/fleet/v4 (Go) Aug 12, 2026
phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration Moderate
CVE-2026-47132 was published for thorsten/phpmyfaq (Composer) Aug 12, 2026
proochicken Credited to proochicken
nimiq-blockchain: Validity store off by one error High
CVE-2026-46369 was published for nimiq-blockchain (Rust) Aug 12, 2026
viquezclaudio Credited to viquezclaudio
LibreNMS: Reflected XSS via Proxmox instance/vmid GET parameters injected into document.title JavaScript assignment Moderate
CVE-2026-45694 was published for librenms/librenms (Composer) Aug 12, 2026
k1bana Credited to k1bana
Winter: Authenticated backend users can bypass Users controller permission checks High
CVE-2026-35445 was published for winter/wn-backend-module (Composer) Aug 12, 2026
everythingBlackkk Credited to everythingBlackkk
Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads Moderate
CVE-2026-32639 was published for winter/wn-cms-module (Composer) Aug 12, 2026
Vincent550102 Credited to Vincent550102
Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax Moderate
CVE-2026-32593 was published for winter/wn-backend-module (Composer) Aug 12, 2026
M9nx Credited to M9nx and turgutAgha turgutAgha turgutAgha
Winter: Stored XSS through Editor Settings custom styles High
CVE-2026-32258 was published for winter/wn-backend-module (Composer) Aug 12, 2026
skyhex19 Credited to skyhex19
Winter: Stored XSS through Brand Settings custom styles High
CVE-2026-32257 was published for winter/wn-backend-module (Composer) Aug 12, 2026
skyhex19 Credited to skyhex19
tablib: Stored XSS in the HTML export via unescaped dataset title Moderate
CVE-2026-9318 was published for tablib (pip) Aug 12, 2026
antonisloukis Credited to antonisloukis
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability Moderate
CVE-2026-62902 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability High
CVE-2026-62871 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability High
CVE-2026-62897 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability High
CVE-2026-70354 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability Moderate
CVE-2026-62909 was published for Microsoft.NETCore.App.Runtime.linux-arm (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability High
CVE-2026-62886 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability High
CVE-2026-62901 was published for Microsoft.NETCore.App.Runtime.linux-arm (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability Moderate
CVE-2026-62899 was published for Microsoft.NETCore.App.Runtime.linux-arm (NuGet) Aug 11, 2026
ProTip! Advisories are also available from the GraphQL API