Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,124 advisories

Loading
Craft CMS: Arbitrary user password reset leading to administrator account takeover High
GHSA-p8x7-9vfw-p7vc was published for craftcms/cms (Composer) Aug 6, 2026
mHe4am Credited to mHe4am
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store High
CVE-2026-70472 was published for flowise (npm) Aug 4, 2026
Kazamayc Credited to Kazamayc
Calico's apiserver wraps tier-scoped resources so that every operation runs through... Moderate Unreviewed
CVE-2026-41187 was published Jul 30, 2026
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 Moderate Unreviewed
CVE-2026-66488 was published Jul 29, 2026
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel Moderate
CVE-2026-49446 was published for github.com/azukaar/cosmos-server (Go) Jul 28, 2026
Dredsen Credited to Dredsen
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions High
CVE-2026-43983 was published for github.com/pocket-id/pocket-id/backend (Go) Jul 28, 2026
kodareef5 Credited to kodareef5
ProTip! Advisories are also available from the GraphQL API