Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

408 advisories

Loading
Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation High
CVE-2026-55212 was published for pimcore/studio-backend-bundle (Composer) Aug 28, 2026
dhairya7760 Credited to dhairya7760
de3erve Credited to de3erve
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key High
CVE-2026-55065 was published for code.vikunja.io/api (Go) Aug 28, 2026
KadirArslan Credited to KadirArslan
Vikunja has a project duplication bypasses write-permission check on the target parent project Moderate
CVE-2026-54766 was published for code.vikunja.io/api (Go) Aug 28, 2026
django CMS: Structure endpoint bypasses page-view permission Moderate
CVE-2026-54624 was published for django-cms (pip) Aug 20, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, 7thParkk, and mauriceng98 Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk mauriceng98 mauriceng98
therawdev Credited to therawdev, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation Moderate
CVE-2026-55236 was published for langgraph-api (pip) Aug 19, 2026
OneThing4101 Credited to OneThing4101
Winter: Authenticated backend users can bypass Users controller permission checks High
CVE-2026-35445 was published for winter/wn-backend-module (Composer) Aug 12, 2026
everythingBlackkk Credited to everythingBlackkk
Craft CMS: Arbitrary user password reset leading to administrator account takeover High
GHSA-p8x7-9vfw-p7vc was published for craftcms/cms (Composer) Aug 6, 2026
mHe4am Credited to mHe4am
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store High
CVE-2026-70472 was published for flowise (npm) Aug 4, 2026
Kazamayc Credited to Kazamayc
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel Moderate
CVE-2026-49446 was published for github.com/azukaar/cosmos-server (Go) Jul 28, 2026
Dredsen Credited to Dredsen
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions High
CVE-2026-43983 was published for github.com/pocket-id/pocket-id/backend (Go) Jul 28, 2026
kodareef5 Credited to kodareef5
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check Critical
CVE-2026-73644 was published for org.openidentityplatform.opendj:opendj-server-legacy (Maven) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF) High
GHSA-pvcr-8mvp-w8qr was published for @budibase/server (npm) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
rexpository Credited to rexpository and Classic298 Classic298 Classic298
marc-zollingkoffer-syzygy Credited to marc-zollingkoffer-syzygy
Gitea: Permanent Fork PR Workflow Approval Gate Bypass High
CVE-2026-58424 was published for code.gitea.io/gitea (Go) Jul 21, 2026
prakhar0x01 Credited to prakhar0x01
@better-auth/sso: SSO provider may allow registration for any org member without a checking their role High
CVE-2026-53515 was published for @better-auth/sso (npm) Jul 20, 2026
Nadav0077 Credited to Nadav0077
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization High
GHSA-x8mg-6r4p-87pf was published for com.arcadedb:arcadedb-server (Maven) Jul 16, 2026
Mitchell45 Credited to Mitchell45
Mitchell45 Credited to Mitchell45
ProTip! Advisories are also available from the GraphQL API