GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
512 advisories
Filter by severity
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
High
GHSA-ppr4-5f46-j9c6
was published
for
@budibase/server
(npm)
Jul 24, 2026
Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL...
Moderate
Unreviewed
CVE-2026-66009
was published
Jul 24, 2026
Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer...
Moderate
Unreviewed
CVE-2026-66008
was published
Jul 24, 2026
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
Moderate
CVE-2026-59943
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing...
High
Unreviewed
CVE-2026-13182
was published
Jul 22, 2026
Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema...
Moderate
Unreviewed
CVE-2026-64627
was published
Jul 21, 2026
SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where...
Moderate
Unreviewed
CVE-2026-63748
was published
Jul 20, 2026
IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed...
Moderate
Unreviewed
CVE-2026-8861
was published
Jul 17, 2026
mcp-memory-keeper: Arbitrary local file read in context_import via unvalidated filePath
Moderate
CVE-2026-54561
was published
for
mcp-memory-keeper
(npm)
Jul 17, 2026
HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages...
Moderate
Unreviewed
CVE-2024-23575
was published
Jul 17, 2026
Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty...
Moderate
Unreviewed
CVE-2026-49365
was published
Jul 6, 2026
Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel...
Moderate
Unreviewed
CVE-2026-56139
was published
Jul 6, 2026
@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state
Moderate
GHSA-qcr8-x557-7cp3
was published
for
@asymmetric-effort/specifyjs
(npm)
Jul 2, 2026
Keycloak Generates an Error Message Containing Sensitive Information
Moderate
CVE-2026-9794
was published
for
org.keycloak:keycloak-services
(Maven)
May 28, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
Moderate
GHSA-6g9v-7gq3-p2c6
was published
for
surrealdb
(Rust)
Jul 1, 2026
Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint...
Moderate
Unreviewed
CVE-2026-56331
was published
Jul 1, 2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain...
Moderate
Unreviewed
CVE-2025-36328
was published
Jun 30, 2026
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is...
Moderate
Unreviewed
CVE-2025-59872
was published
Jun 17, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
High
GHSA-cc8f-fcx3-gpjr
was published
for
surrealdb
(Rust)
Jun 19, 2026
canto-saas-api: OAuth credentials exposed in URL query string and exception messages
Moderate
CVE-2026-55375
was published
for
jleehr/canto-saas-api
(Composer)
Jun 19, 2026
Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information
Moderate
CVE-2024-21733
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Jan 19, 2024
Keycloak's identity-first login flow exposes user information
Low
CVE-2026-4633
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 23, 2026
Parse Server's GraphQL "Did you mean ...?" validation suggestions disclose schema to unauthenticated callers
Moderate
CVE-2026-47248
was published
for
parse-server
(npm)
May 29, 2026
Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token
Critical
CVE-2026-48039
was published
for
meta-ads-mcp
(pip)
Jun 11, 2026
ProTip!
Advisories are also available from the
GraphQL API