Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,454 advisories

Loading
PraisonAI: Platform members can delete owner issue dependencies through member-owned related issues Moderate
CVE-2026-62179 was published for praisonai-platform (pip) Oct 7, 2026
rexpository Credited to rexpository
rexpository Credited to rexpository
dinhvaren Credited to dinhvaren
xIllunight Credited to xIllunight and MatissJanis MatissJanis MatissJanis
wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry Moderate
CVE-2026-46438 was published for wger (pip) Oct 7, 2026
KadirArslan Credited to KadirArslan
wger: Trainer Privilege Escalation - Improper Privilege Management High
CVE-2026-46434 was published for wger (pip) Oct 7, 2026
KadirArslan Credited to KadirArslan
wger: API credentials remain valid after logout/password change Moderate
CVE-2026-46437 was published for wger (pip) Oct 7, 2026
VashuVats Credited to VashuVats
wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding Moderate
CVE-2026-45161 was published for wger (pip) Oct 7, 2026
whatisproblem Credited to whatisproblem
wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views) High
CVE-2026-43976 was published for wger (pip) Oct 7, 2026
whatisproblem Credited to whatisproblem
Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter flooding High
CVE-2026-41510 was published for github.com/corazawaf/coraza/v3 (Go) Oct 6, 2026
fzipi Credited to fzipi and WalTeR-RE WalTeR-RE WalTeR-RE
Coraza: Truncated multipart body bypasses MULTIPART_STRICT_ERROR (rule 200003) via silent io.ErrUnexpectedEOF handling Moderate
CVE-2026-41508 was published for github.com/corazawaf/coraza/v3 (Go) Oct 6, 2026
fzipi Credited to fzipi
Coraza: Native audit-log format allows CRLF injection and log forgery via request body and header fields Moderate
CVE-2026-41504 was published for github.com/corazawaf/coraza/v3 (Go) Oct 6, 2026
fzipi Credited to fzipi
knowns OS Command Injection via Insecure LSP Binary Path Config in .knowns/config.json High
CVE-2026-86540 was published for knowns (npm) Oct 6, 2026
uziii2208 Credited to uziii2208 and hoanggxyuuki hoanggxyuuki hoanggxyuuki
Payload didn't enforce field-level password update restrictions High
CVE-2026-105855 was published for payload (npm) Oct 6, 2026
pavelkohout396 Credited to pavelkohout396
Payload: ReDoS in Multipart Content-Type Validation High
CVE-2026-105854 was published for payload (npm) Oct 6, 2026
hwpark6804-gif Credited to hwpark6804-gif
Payload vulnerable to API key disclosure through ordinary document reads High
CVE-2026-105849 was published for payload (npm) Oct 6, 2026
Zerotistic Credited to Zerotistic
Payload Ecommerce has an order confirmation validation issue High
CVE-2026-105850 was published for @payloadcms/plugin-ecommerce (npm) Oct 6, 2026
Payload relationship-query authorization bypass Moderate
CVE-2026-105852 was published for payload (npm) Oct 6, 2026
Payload: Token refresh and password reset responses may expose restricted user fields High
CVE-2026-105853 was published for payload (npm) Oct 6, 2026
Payload: Field access control bypass on auth collections Critical
CVE-2026-105851 was published for payload (npm) Oct 6, 2026
Zerotistic Credited to Zerotistic
Payload: Insufficient Access Control in Stripe REST Proxy Moderate
CVE-2026-105848 was published for @payloadcms/plugin-stripe (npm) Oct 6, 2026
Payload: Improper access control for MCP API keys High
CVE-2026-105806 was published for @payloadcms/plugin-mcp (npm) Oct 6, 2026
pavelkohout396 Credited to pavelkohout396
Payload: Prototype pollution in Payload Import Export plugin Critical
CVE-2026-105844 was published for @payloadcms/plugin-import-export (npm) Oct 6, 2026
iamnoooob Credited to iamnoooob
Payload: SQL Injection in SQLite and Postgres Critical
CVE-2026-105845 was published for payload (npm) Oct 6, 2026
Payload: Untrusted redirect URL parameter exploit Moderate
CVE-2026-105846 was published for @payloadcms/next (npm) Oct 6, 2026
kullai-secasure Credited to kullai-secasure and yuvraj-secasure yuvraj-secasure yuvraj-secasure
ProTip! Advisories are also available from the GraphQL API