GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
36,454 advisories
Filter by severity
PraisonAI: Platform members can delete owner issue dependencies through member-owned related issues
Moderate
CVE-2026-62179
was published
for
praisonai-platform
(pip)
Oct 7, 2026
PraisonAI: AgentMail webhook mode accepts forged unsigned message.received events and invokes agents
High
CVE-2026-61436
was published
for
praisonai
(pip)
Oct 7, 2026
PraisonAI: AgentMail webhook lacks signature verification, allowing unauthenticated message injection and sender spoofing
High
CVE-2026-61428
was published
for
praisonai
(pip)
Oct 7, 2026
Actual Sync Server: CORS Proxy GitHub API Allowlist Prefix Bypass Leaks Private Repositories Through the Server GitHub Token
High
CVE-2026-57449
was published
for
@actual-app/sync-server
(npm)
Oct 7, 2026
wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry
Moderate
CVE-2026-46438
was published
for
wger
(pip)
Oct 7, 2026
wger: Trainer Privilege Escalation - Improper Privilege Management
High
CVE-2026-46434
was published
for
wger
(pip)
Oct 7, 2026
wger: API credentials remain valid after logout/password change
Moderate
CVE-2026-46437
was published
for
wger
(pip)
Oct 7, 2026
wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding
Moderate
CVE-2026-45161
was published
for
wger
(pip)
Oct 7, 2026
wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views)
High
CVE-2026-43976
was published
for
wger
(pip)
Oct 7, 2026
Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter flooding
High
CVE-2026-41510
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 6, 2026
Coraza: Truncated multipart body bypasses MULTIPART_STRICT_ERROR (rule 200003) via silent io.ErrUnexpectedEOF handling
Moderate
CVE-2026-41508
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 6, 2026
Coraza: Native audit-log format allows CRLF injection and log forgery via request body and header fields
Moderate
CVE-2026-41504
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 6, 2026
knowns OS Command Injection via Insecure LSP Binary Path Config in .knowns/config.json
High
CVE-2026-86540
was published
for
knowns
(npm)
Oct 6, 2026
Payload didn't enforce field-level password update restrictions
High
CVE-2026-105855
was published
for
payload
(npm)
Oct 6, 2026
Payload: ReDoS in Multipart Content-Type Validation
High
CVE-2026-105854
was published
for
payload
(npm)
Oct 6, 2026
Payload vulnerable to API key disclosure through ordinary document reads
High
CVE-2026-105849
was published
for
payload
(npm)
Oct 6, 2026
Payload Ecommerce has an order confirmation validation issue
High
CVE-2026-105850
was published
for
@payloadcms/plugin-ecommerce
(npm)
Oct 6, 2026
Payload relationship-query authorization bypass
Moderate
CVE-2026-105852
was published
for
payload
(npm)
Oct 6, 2026
Payload: Token refresh and password reset responses may expose restricted user fields
High
CVE-2026-105853
was published
for
payload
(npm)
Oct 6, 2026
Payload: Field access control bypass on auth collections
Critical
CVE-2026-105851
was published
for
payload
(npm)
Oct 6, 2026
Payload: Insufficient Access Control in Stripe REST Proxy
Moderate
CVE-2026-105848
was published
for
@payloadcms/plugin-stripe
(npm)
Oct 6, 2026
Payload: Improper access control for MCP API keys
High
CVE-2026-105806
was published
for
@payloadcms/plugin-mcp
(npm)
Oct 6, 2026
Payload: Prototype pollution in Payload Import Export plugin
Critical
CVE-2026-105844
was published
for
@payloadcms/plugin-import-export
(npm)
Oct 6, 2026
Payload: SQL Injection in SQLite and Postgres
Critical
CVE-2026-105845
was published
for
payload
(npm)
Oct 6, 2026
Payload: Untrusted redirect URL parameter exploit
Moderate
CVE-2026-105846
was published
for
@payloadcms/next
(npm)
Oct 6, 2026
ProTip!
Advisories are also available from the
GraphQL API