GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,894
Maven
5,000+
npm
5,000+
NuGet
963
pip
5,000+
Pub
13
RubyGems
1,061
Rust
1,373
Swift
54
Unreviewed advisories
All unreviewed
5,000+
2,189 advisories
Filter by severity
@hulumi/baseline: CloudTrail selector tampering events were not fully detected
Moderate
GHSA-gfp8-mp24-5vxg
was published
for
@hulumi/baseline
(npm)
May 21, 2026
NocoDB: Shared-base link access can invite arbitrary users as persistent base members
Moderate
CVE-2026-46552
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion
Moderate
CVE-2026-46551
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: Refresh Token Cookie Set Without `secure` and `sameSite` Flags
Moderate
CVE-2026-46550
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams)
Moderate
CVE-2026-46548
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL
Moderate
CVE-2026-46547
was published
for
nocodb
(npm)
May 21, 2026
@sveltejs/kit: `query.batch` cross-talk
Moderate
GHSA-hgv7-v322-mmgr
was published
for
@sveltejs/kit
(npm)
May 21, 2026
Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows
Moderate
GHSA-c2c9-mfw7-p8hw
was published
for
flowise
(npm)
May 20, 2026
Flowise: Mass Assignment in PUT /api/v1/user Allows Authenticated Users to Override Password Hash and Bypass Password Change Verification
Moderate
GHSA-59fh-9f3p-7m39
was published
for
flowise
(npm)
May 20, 2026
Flowise: Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse from any webpage
Moderate
GHSA-m837-xvxr-vqwg
was published
for
flowise
(npm)
May 20, 2026
HAX CMS: Denial of Service using Malicious Import Request
Moderate
CVE-2026-46357
was published
for
@haxtheweb/haxcms-nodejs
(npm)
May 19, 2026
Trubo: Login callback CSRF/session fixation
Moderate
CVE-2026-45773
was published
for
turbo
(npm)
May 19, 2026
Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching
Moderate
CVE-2026-46341
was published
for
@apify/actors-mcp-server
(npm)
May 19, 2026
Budibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 Hour
Moderate
CVE-2026-46424
was published
for
@budibase/backend-core
(npm)
May 19, 2026
protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion
Moderate
CVE-2026-45740
was published
for
protobufjs
(npm)
May 19, 2026
n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass
Moderate
GHSA-3875-8gcx-7v46
was published
for
n8n
(npm)
May 19, 2026
n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions
Moderate
GHSA-2vx9-7wpg-88jq
was published
for
n8n
(npm)
May 19, 2026
Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)
Moderate
CVE-2026-45670
was published
for
@nuxt/rspack-builder
(npm)
May 19, 2026
Nuxt: Reflected XSS in `navigateTo()` external redirect
Moderate
CVE-2026-45669
was published
for
nuxt
(npm)
May 19, 2026
HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft
Moderate
CVE-2026-46496
was published
for
@haxtheweb/haxcms-nodejs
(npm)
May 19, 2026
Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API
Moderate
CVE-2026-45719
was published
for
@budibase/server
(npm)
May 18, 2026
Budibase: Row Action Trigger Bypasses View Row Filter Security Boundary Allowing Action on Out-of-Scope Rows
Moderate
CVE-2026-45718
was published
for
budibase
(npm)
May 18, 2026
brace-expansion: Large numeric range defeats documented `max` DoS protection
Moderate
CVE-2026-45149
was published
for
brace-expansion
(npm)
May 18, 2026
Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass
Moderate
CVE-2026-45577
was published
for
neotoma
(npm)
May 18, 2026
ProTip!
Advisories are also available from the
GraphQL API