Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,508 advisories

Loading
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints High
CVE-2026-73841 was published for github.com/openchoreo/openchoreo (Go) Sep 2, 2026
ihopenre-eng Credited to ihopenre-eng
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths High
CVE-2026-72921 was published for github.com/seaweedfs/seaweedfs (Go) Sep 2, 2026
KadirArslan Credited to KadirArslan
EasyAdmin custom-action dispatcher bypasses access_control on other routes High
CVE-2026-81892 was published for easycorp/easyadmin-bundle (Composer) Sep 2, 2026
TungNGo02 Credited to TungNGo02
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in... High Unreviewed
CVE-2026-82463 was published Aug 29, 2026
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass High
CVE-2026-55638 was published for 9router (npm) Aug 28, 2026
dinhvaren Credited to dinhvaren
black-shadow-007 Credited to black-shadow-007
Snipe-IT has an authorization bypass on bulk editing users High
CVE-2026-55460 was published for snipe/snipe-it (Composer) Aug 28, 2026
mamdouhmahfouz Credited to mamdouhmahfouz
ProTip! Advisories are also available from the GraphQL API