Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

384 advisories

Loading
Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation High
CVE-2026-55212 was published for pimcore/studio-backend-bundle (Composer) Aug 28, 2026
dhairya7760 Credited to dhairya7760
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key High
CVE-2026-55065 was published for code.vikunja.io/api (Go) Aug 28, 2026
KadirArslan Credited to KadirArslan
therawdev Credited to therawdev, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
Winter: Authenticated backend users can bypass Users controller permission checks High
CVE-2026-35445 was published for winter/wn-backend-module (Composer) Aug 12, 2026
everythingBlackkk Credited to everythingBlackkk
Craft CMS: Arbitrary user password reset leading to administrator account takeover High
GHSA-p8x7-9vfw-p7vc was published for craftcms/cms (Composer) Aug 6, 2026
mHe4am Credited to mHe4am
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store High
CVE-2026-70472 was published for flowise (npm) Aug 4, 2026
Kazamayc Credited to Kazamayc
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions High
CVE-2026-43983 was published for github.com/pocket-id/pocket-id/backend (Go) Jul 28, 2026
kodareef5 Credited to kodareef5
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF) High
GHSA-pvcr-8mvp-w8qr was published for @budibase/server (npm) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
Gitea: Permanent Fork PR Workflow Approval Gate Bypass High
CVE-2026-58424 was published for code.gitea.io/gitea (Go) Jul 21, 2026
prakhar0x01 Credited to prakhar0x01
ProTip! Advisories are also available from the GraphQL API