Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

33,978 advisories

Loading
mathlive's Lack of Escaping of HTML allows for XSS Moderate
CVE-2026-54705 was published for mathlive (npm) Jul 29, 2026
CosmicCrusader23 Credited to CosmicCrusader23
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords Moderate
CVE-2026-54704 was published for io.opentelemetry.javaagent:opentelemetry-javaagent (Maven) Jul 29, 2026
FWinkler79 Credited to FWinkler79
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion Moderate
CVE-2026-54712 was published for io.opentelemetry.javaagent:opentelemetry-javaagent (Maven) Jul 29, 2026
decsecre583 Credited to decsecre583
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal Low
GHSA-pmwx-rm49-xv39 was published for activerecord-tenanted (RubyGems) Jul 29, 2026
tonghuaroot Credited to tonghuaroot
netfoil: Incorrect block responses could lead to localhost traffic High
GHSA-xvg2-cgv6-6h7v was published for github.com/tinfoil-factory/netfoil (Go) Jul 29, 2026
Logging operator has Fluentd configuration injection that allows remote code execution Critical
CVE-2026-54680 was published for github.com/kube-logging/logging-operator (Go) Jul 29, 2026
hnts Credited to hnts
ZITADEL Users Can Self-Verify Email/Phone via API High
CVE-2026-54693 was published for github.com/zitadel/zitadel (Go) Jul 29, 2026
IAM-marco Credited to IAM-marco and livio-a livio-a livio-a
proot-distro has a Container Isolation Bypass via Crafted Restore Archive High
CVE-2026-54727 was published for proot-distro (pip) Jul 29, 2026
x0root Credited to x0root
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive High
CVE-2026-54574 was published for proot-distro (pip) Jul 29, 2026
x0root Credited to x0root
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS Low
CVE-2026-52838 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
ashrexon Credited to ashrexon
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync Low
CVE-2026-52841 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
Dredsen Credited to Dredsen
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page Moderate
CVE-2026-52837 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
peoplstar Credited to peoplstar
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass Low
CVE-2026-52839 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
ashrexon Credited to ashrexon
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network Low
CVE-2026-52840 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
Dredsen Credited to Dredsen
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure High
CVE-2026-55651 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
0xmupa Credited to 0xmupa
olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193 Moderate
GHSA-wchh-9x6h-7f6p was published for matrix-commander (pip) Jul 29, 2026
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping High
CVE-2026-11393 was published for @aws/agentcore (npm) Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction Critical
CVE-2026-54735 was published for github.com/prebid/prebid-server (Go) Jul 29, 2026
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities High
CVE-2026-50559 was published for io.quarkus:quarkus-vertx-http (Maven) Jul 29, 2026
geoand Credited to geoand and cescoffier cescoffier cescoffier
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate Low
GHSA-pc2w-4mq8-32qw was published for @dynatrace-oss/dynatrace-mcp-server (npm) Jul 29, 2026
yotampe-pluto Credited to yotampe-pluto
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive Moderate
CVE-2026-50558 was published for penelope-shell-handler (pip) Jul 29, 2026
strikoder Credited to strikoder
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type Moderate
CVE-2026-49756 was published for req (Erlang) Jul 29, 2026
PJUllrich Credited to PJUllrich and maennchen maennchen maennchen
Req vulnerable to unbounded archive/compression extraction triggered by response content-type High
CVE-2026-49755 was published for req (Erlang) Jul 29, 2026
PJUllrich Credited to PJUllrich and maennchen maennchen maennchen
veraPDF Parser DoS via PostScript Type 1 Font Programs Moderate
CVE-2026-54081 was published for org.verapdf:parser (Maven) Jul 29, 2026
wodzen Credited to wodzen
veraPDF Parser DoS via PostScript CMap Streams Moderate
CVE-2026-54080 was published for org.verapdf:parser (Maven) Jul 29, 2026
wodzen Credited to wodzen
ProTip! Advisories are also available from the GraphQL API