Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,128 advisories

Loading
HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information... Moderate Unreviewed
CVE-2026-56457 was published Jun 29, 2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure... Moderate Unreviewed
CVE-2025-59868 was published Jun 27, 2026
WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs Moderate
GHSA-q683-8468-r6h6 was published for web-auth/webauthn-symfony-bundle (Composer) Jun 26, 2026
PGHoard: Password written to debug log Low
CVE-2026-54711 was published for pghoard (pip) Jun 18, 2026
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router Moderate
CVE-2026-54236 was published for vllm (pip) Jun 17, 2026
SnailSploit Credited to SnailSploit and jperezdealgaba jperezdealgaba jperezdealgaba
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs) Moderate
CVE-2026-47768 was published for github.com/juev/nebula-mesh (Go) Jun 10, 2026
ak2k Credited to ak2k
Admidio writes session IDs and auto-login cookie values to application logs Moderate
CVE-2026-47234 was published for admidio/admidio (Composer) May 29, 2026
0x2face Credited to 0x2face, spect3r1, 0xreizouko, ADHAM-KHAIRY, BabaYaga0x01, 00xCanelo, and 0xheg3zy spect3r1 spect3r1
0xreizouko 0xreizouko ADHAM-KHAIRY ADHAM-KHAIRY BabaYaga0x01 BabaYaga0x01 00xCanelo 00xCanelo 0xheg3zy 0xheg3zy
ProTip! Advisories are also available from the GraphQL API