Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

566 advisories

Loading
de3erve Credited to de3erve
Vikunja has a project duplication bypasses write-permission check on the target parent project Moderate
CVE-2026-54766 was published for code.vikunja.io/api (Go) Aug 28, 2026
A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function... Moderate Unreviewed
CVE-2026-78887 was published Aug 25, 2026
django CMS: Structure endpoint bypasses page-view permission Moderate
CVE-2026-54624 was published for django-cms (pip) Aug 20, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, 7thParkk, and mauriceng98 Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk mauriceng98 mauriceng98
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation Moderate
CVE-2026-55236 was published for langgraph-api (pip) Aug 19, 2026
OneThing4101 Credited to OneThing4101
Calico's apiserver wraps tier-scoped resources so that every operation runs through... Moderate Unreviewed
CVE-2026-41187 was published Jul 30, 2026
Duplicate Advisory: Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets Moderate
GHSA-rqjw-r5g4-x8qm was published for craftcms/cms (Composer) Jul 6, 2026 withdrawn
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 Moderate Unreviewed
CVE-2026-66488 was published Jul 29, 2026
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel Moderate
CVE-2026-49446 was published for github.com/azukaar/cosmos-server (Go) Jul 28, 2026
Dredsen Credited to Dredsen
ProTip! Advisories are also available from the GraphQL API