Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,203 advisories

Loading
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions Critical
CVE-2026-77415 was published for jsonata (npm) Aug 21, 2026
c0rydoras Credited to c0rydoras
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions Critical
CVE-2026-77414 was published for jsonata (npm) Aug 21, 2026
c0rydoras Credited to c0rydoras
JSONata: Arbitrary Code Execution via crafted JSONata expressions Critical
CVE-2026-77413 was published for jsonata (npm) Aug 21, 2026
peaktwilight Credited to peaktwilight and c0rydoras c0rydoras c0rydoras
Keystone vulnerable to `graphql.maxTake` bypass with negative `take` High
CVE-2026-63421 was published for @keystone-6/core (npm) Aug 21, 2026
Haxset Credited to Haxset
Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors High
CVE-2026-61824 was published for defuddle (npm) Aug 21, 2026
Mr-DJ Credited to Mr-DJ
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter High
CVE-2026-63462 was published for unleash-server (npm) Aug 21, 2026
kah-ja Credited to kah-ja
gettext-converter: Prototype pollution in js2i18next() via crafted translation keys Moderate
CVE-2026-55451 was published for gettext-converter (npm) Aug 20, 2026
Dremig Credited to Dremig
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution High
GHSA-ghvf-qf6h-g8x5 was published for @nocobase/server (npm) Aug 20, 2026
lukehebe Credited to lukehebe
Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication Critical
CVE-2026-55445 was published for @whyour/qinglong (npm) Aug 20, 2026
decsecre583 Credited to decsecre583
node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS High
CVE-2026-54156 was published for node-opcua (npm) Aug 20, 2026
stanleytobias Credited to stanleytobias
node-opcua missing nonce verification in UserNameIdentityToken authentication High
CVE-2026-54155 was published for node-opcua (npm) Aug 20, 2026
stanleytobias Credited to stanleytobias
next-video: Unauthenticated arbitrary file read via /api/video request handler Moderate
CVE-2026-54150 was published for next-video (npm) Aug 20, 2026
NocoBase backup restore schema name allows command injection Moderate
CVE-2026-55410 was published for @nocobase/plugin-backups (npm) Aug 20, 2026
sondt99 Credited to sondt99
Zwique Credited to Zwique
StarPlatinu Credited to StarPlatinu
logto-tunnel serves files outside --experience-path via path traversal High
CVE-2026-63188 was published for @logto/tunnel (npm) Aug 19, 2026
pyuysig Credited to pyuysig
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses Moderate
GHSA-hjwh-xvfw-qrwj was published for mcp-searxng (npm) Aug 19, 2026
NARKHEDE-VAIBHAV Credited to NARKHEDE-VAIBHAV
SearXNG MCP Server: Additional hardened-mode SSRF bypasses Moderate
CVE-2026-54689 was published for mcp-searxng (npm) Aug 19, 2026
geo-chen Credited to geo-chen
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools High
GHSA-rr55-jp92-8wp2 was published for claude-faf-mcp (npm) Aug 19, 2026
faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools High
GHSA-j4r7-8ph4-43g3 was published for faf-mcp (npm) Aug 19, 2026
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools High
GHSA-cc2g-gq8c-r332 was published for grok-faf-mcp (npm) Aug 19, 2026
ProTip! Advisories are also available from the GraphQL API