GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
43
Go
3,164
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,458
Pub
12
RubyGems
991
Rust
1,184
Swift
50
Unreviewed advisories
All unreviewed
5,000+
50 advisories
Filter by severity
TinaCMS CLI Dev Server Vulnerable to Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS
Critical
CVE-2026-28792
was published
for
@tinacms/cli
(npm)
Mar 12, 2026
mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft
High
GHSA-g9rg-8vq5-mpwm
was published
for
mcp-memory-service
(pip)
Mar 7, 2026
A permissive web security configuration may allow cross-origin restrictions enforced by modern...
Low
Unreviewed
CVE-2025-9292
was published
Feb 13, 2026
Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins
High
CVE-2026-25478
was published
for
litestar
(pip)
Feb 9, 2026
Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js...
Moderate
Unreviewed
CVE-2025-13984
was published
Jan 28, 2026
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) implement an...
High
Unreviewed
CVE-2026-24435
was published
Jan 26, 2026
OpenCode's Unauthenticated HTTP Server Allows Arbitrary Command Execution
High
CVE-2026-22812
was published
for
opencode-ai
(npm)
Jan 13, 2026
A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker...
Moderate
Unreviewed
CVE-2025-55462
was published
Jan 13, 2026
Same-origin policy bypass in the DOM: Workers component. This vulnerability affects Firefox < 145...
High
Unreviewed
CVE-2025-13019
was published
Nov 11, 2025
Same-origin policy bypass in the DOM: Notifications component. This vulnerability affects Firefox...
High
Unreviewed
CVE-2025-13017
was published
Nov 11, 2025
The issue was addressed with improved checks. This issue is fixed in Safari 26.1, visionOS 26.1,...
High
Unreviewed
CVE-2025-43480
was published
Nov 4, 2025
The issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1,...
Moderate
Unreviewed
CVE-2025-43392
was published
Nov 4, 2025
Strapi core vulnerable to sensitive data exposure via CORS misconfiguration
High
CVE-2025-53092
was published
for
@strapi/core
(npm)
Oct 16, 2025
IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains...
Moderate
Unreviewed
CVE-2023-37401
was published
Oct 9, 2025
Incorrect Cross-Origin Resource Sharing (CORS) configuration in Hiberus Sintra. Cross-Origin...
Moderate
Unreviewed
CVE-2025-41010
was published
Oct 2, 2025
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird...
Moderate
Unreviewed
CVE-2025-10529
was published
Sep 16, 2025
@musistudio/claude-code-router has improper CORS configuration
High
CVE-2025-57755
was published
for
@musistudio/claude-code-router
(npm)
Aug 21, 2025
IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could...
Moderate
Unreviewed
CVE-2025-27909
was published
Aug 18, 2025
An unauthenticated remote attacker can take advantage of the current overly permissive CORS...
High
Unreviewed
CVE-2025-25264
was published
Jun 16, 2025
In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross...
Moderate
Unreviewed
CVE-2025-41363
was published
Jun 6, 2025
In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross...
Moderate
Unreviewed
CVE-2025-41366
was published
Jun 6, 2025
Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious...
High
Unreviewed
CVE-2025-25234
was published
Apr 17, 2025
SaTECH BCU, in its firmware version 2.1.3, could allow XSS attacks and other malicious resources...
Low
Unreviewed
CVE-2025-2865
was published
Mar 28, 2025
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin...
Moderate
Unreviewed
CVE-2024-22348
was published
Jan 20, 2025
IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a...
Moderate
Unreviewed
CVE-2024-45642
was published
Nov 14, 2024
ProTip!
Advisories are also available from the
GraphQL API