GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
43
Go
3,143
Maven
5,000+
npm
5,000+
NuGet
840
pip
4,439
Pub
12
RubyGems
990
Rust
1,174
Swift
50
Unreviewed advisories
All unreviewed
5,000+
9,462 advisories
Filter by severity
.NET Denial of Service Vulnerability
High
CVE-2026-26127
was published
for
Microsoft.Bcl.Memory
(NuGet)
Mar 11, 2026
.NET Denial of Service Vulnerability
High
CVE-2026-26130
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Mar 11, 2026
.NET Elevation of Privilege Vulnerability
High
CVE-2026-26131
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Mar 11, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
High
CVE-2026-31892
was published
for
github.com/argoproj/argo-workflows
(Go)
Mar 11, 2026
Shopware vulnerable to a potential take over of app credentials
High
CVE-2026-31889
was published
for
shopware/core
(Composer)
Mar 11, 2026
Shopware: Unauthenticated data extraction possible through store-api.order endpoint
High
CVE-2026-31887
was published
for
shopware/core
(Composer)
Mar 11, 2026
CraftCMS has an RCE vulnerability via relational conditionals in the control panel
High
CVE-2026-31857
was published
for
craftcms/cms
(Composer)
Mar 11, 2026
Striae has a hash validation utility vulnerability
High
CVE-2026-31839
was published
for
@striae-org/striae
(npm)
Mar 11, 2026
Umbraco Affected by Vertical Privilege Escalation via Missing Authorization Checks
High
CVE-2026-31834
was published
for
Umbraco.Cms
(NuGet)
Mar 11, 2026
Unauthorized access to Argo Workflows Template
High
CVE-2026-28229
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Mar 11, 2026
@siteboon/claude-code-ui Vulnerable to Unauthenticated RCE via WebSocket Shell Injection
High
CVE-2026-31975
was published
for
@siteboon/claude-code-ui
(npm)
Mar 11, 2026
Parse Server's MFA recovery codes not consumed after use
High
CVE-2026-31875
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server has a protected fields bypass via dot-notation in query and sort
High
CVE-2026-31872
was published
for
parse-server
(npm)
Mar 11, 2026
flagd Vulnerable to Allocation of Resources Without Limits or Throttling
High
CVE-2026-31866
was published
for
github.com/open-feature/flagd/flagd
(Go)
Mar 11, 2026
CraftCMS's `ElementSearchController` Affected by Blind SQL Injection
High
CVE-2026-31858
was published
for
craftcms/cms
(Composer)
Mar 11, 2026
sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digest
High
CVE-2026-31830
was published
for
sigstore
(RubyGems)
Mar 11, 2026
Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access
High
CVE-2026-31829
was published
for
flowise
(npm)
Mar 11, 2026
Parse Server: Classes `_GraphQLConfig` and `_Audience` master key bypass via generic class routes
High
CVE-2026-31800
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server OAuth2 authentication adapter account takeover via identity spoofing
High
CVE-2026-30967
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server has a protected fields bypass via logical query operators
High
CVE-2026-30962
was published
for
parse-server
(npm)
Mar 11, 2026
Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type
High
CVE-2026-30951
was published
for
sequelize
(npm)
Mar 11, 2026
Parse Server missing audience validation in Keycloak authentication adapter
High
CVE-2026-30949
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server vulnerable to stored cross-site scripting (XSS) via SVG file upload
High
CVE-2026-30948
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server has a bypass of class-level permissions in LiveQuery
High
CVE-2026-30947
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API
High
CVE-2026-30946
was published
for
parse-server
(npm)
Mar 11, 2026
ProTip!
Advisories are also available from the
GraphQL API