Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,164 advisories

Loading
The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the... Critical Unreviewed
CVE-2026-80203 was published Aug 29, 2026
TA-MU-TA Credited to TA-MU-TA
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass High
CVE-2026-55638 was published for 9router (npm) Aug 28, 2026
dinhvaren Credited to dinhvaren
black-shadow-007 Credited to black-shadow-007
Snipe-IT has incorrect permission for legacy license checkin API Moderate
CVE-2026-55479 was published for snipe/snipe-it (Composer) Aug 28, 2026
Mitchell45 Credited to Mitchell45
Snipe-IT's import created_by can be overwritten Moderate
CVE-2026-55475 was published for snipe/snipe-it (Composer) Aug 28, 2026
ashrexon Credited to ashrexon
Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation Moderate
CVE-2026-55472 was published for snipe/snipe-it (Composer) Aug 28, 2026
Mitchell45 Credited to Mitchell45
Snipe-IT has an authorization bypass on print inventory page Moderate
CVE-2026-55462 was published for snipe/snipe-it (Composer) Aug 28, 2026
mamdouhmahfouz Credited to mamdouhmahfouz
Snipe-IT has an authorization bypass on bulk editing users High
CVE-2026-55460 was published for snipe/snipe-it (Composer) Aug 28, 2026
mamdouhmahfouz Credited to mamdouhmahfouz
Vikunja has a project duplication bypasses write-permission check on the target parent project Moderate
CVE-2026-54766 was published for code.vikunja.io/api (Go) Aug 28, 2026
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root High
CVE-2026-54563 was published for github.com/cloudreve/Cloudreve/v3 (Go) Aug 26, 2026
riodrwn Credited to riodrwn
ProTip! Advisories are also available from the GraphQL API