GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
668 advisories
Filter by severity
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the...
High
Unreviewed
CVE-2026-84482
was published
Sep 2, 2026
TYPO3 CMS - Broken Access Control in Backend and Install Tool
High
CVE-2026-19418
was published
for
typo3/cms-backend
(Composer)
Sep 1, 2026
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox...
Critical
Unreviewed
CVE-2026-84129
was published
Sep 1, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2026-70309
was published
Aug 28, 2026
Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual...
Low
Unreviewed
CVE-2026-59297
was published
Aug 27, 2026
tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying...
High
Unreviewed
CVE-2026-81099
was published
Aug 27, 2026
The Dash MCP server bound its listener to the loopback address but never checked the host a...
Low
Unreviewed
CVE-2026-81102
was published
Aug 27, 2026
tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the...
High
Unreviewed
CVE-2026-81100
was published
Aug 27, 2026
pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK...
High
Unreviewed
CVE-2026-81095
was published
Aug 27, 2026
mcp-go accepted requests on its HTTP transports without checking the Host header....
High
Unreviewed
CVE-2026-81092
was published
Aug 27, 2026
genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport
High
CVE-2026-55637
was published
for
github.com/geiserx/genieacs-mcp
(Go)
Aug 25, 2026
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
High
CVE-2026-55532
was published
for
PraisonAI
(pip)
Aug 25, 2026
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
Moderate
CVE-2026-55529
was published
for
PraisonAI
(pip)
Aug 25, 2026
Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages:...
Critical
Unreviewed
CVE-2026-72702
was published
Aug 25, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
Moderate
CVE-2026-67448
was published
for
github.com/axllent/mailpit
(Go)
Aug 20, 2026
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component:...
High
Unreviewed
CVE-2026-62442
was published
Aug 18, 2026
Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing)....
High
Unreviewed
CVE-2026-60765
was published
Aug 18, 2026
Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in...
High
Unreviewed
CVE-2026-74981
was published
Aug 18, 2026
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154 and...
Moderate
Unreviewed
CVE-2026-74970
was published
Aug 18, 2026
Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in...
Moderate
Unreviewed
CVE-2026-74974
was published
Aug 18, 2026
Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in...
Moderate
Unreviewed
CVE-2026-74968
was published
Aug 18, 2026
Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in...
Moderate
Unreviewed
CVE-2026-74967
was published
Aug 18, 2026
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in...
Moderate
Unreviewed
CVE-2026-74963
was published
Aug 18, 2026
Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in...
High
Unreviewed
CVE-2026-74962
was published
Aug 18, 2026
SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin...
Low
Unreviewed
CVE-2026-74802
was published
Aug 17, 2026
ProTip!
Advisories are also available from the
GraphQL API