GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,821
Maven
5,000+
npm
5,000+
NuGet
939
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
421 advisories
Filter by severity
Portainer has an endpoint security bypass via Swarm service create/update
Critical
CVE-2026-44849
was published
for
github.com/portainer/portainer
(Go)
May 14, 2026
Portainer missing authorization on Docker plugin endpoints, which allows host RCE
Critical
CVE-2026-44848
was published
for
github.com/portainer/portainer
(Go)
May 14, 2026
SiYuan Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code execution
Critical
CVE-2026-45375
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
May 13, 2026
Obot has an authorization bypass in /mcp-connect/{id} that allows any authenticated user to use any registered MCP server
Critical
GHSA-vw82-7fv8-r6gp
was published
for
github.com/obot-platform/obot
(Go)
May 13, 2026
esm.sh: Legacy Route Path Traversal Can Lead to RCE
Critical
CVE-2026-44593
was published
for
github.com/esm-dev/esm.sh
(Go)
May 12, 2026
Dalfox Server Mode Vulnerable to Unauthenticated Remote Code Execution via `found-action`
Critical
CVE-2026-45087
was published
for
github.com/hahwul/dalfox/v2
(Go)
May 12, 2026
CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE
Critical
CVE-2026-44477
was published
for
github.com/cloudnative-pg/cloudnative-pg
(Go)
May 11, 2026
free5GC's NEF nnef-pfdmanagement API is unauthenticated; forged bearer tokens can read PFD data and create/delete PFD subscriptions
Critical
CVE-2026-44330
was published
for
github.com/free5gc/nef
(Go)
May 8, 2026
free5GC's SMF UPI management interface lacks auth middleware; unauthenticated topology read/write requests reach handlers
Critical
CVE-2026-44329
was published
for
github.com/free5gc/smf
(Go)
May 8, 2026
free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler
Critical
CVE-2026-44327
was published
for
github.com/free5gc/nef
(Go)
May 8, 2026
free5GC's NEF 3gpp-traffic-influence API is unauthenticated; missing or forged bearer tokens can create, read, patch, and delete subscriptions
Critical
CVE-2026-44326
was published
for
github.com/free5gc/nef
(Go)
May 8, 2026
free5GC's NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens can create, read, and delete PFD transactions
Critical
CVE-2026-44315
was published
for
github.com/free5gc/nef
(Go)
May 8, 2026
SiYuan: Electron Renderer RCE via decodeURIComponent-driven tooltip XSS in aria-label sink (incomplete fix for CVE-2026-34585)
Critical
CVE-2026-44588
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
May 8, 2026
SiYuan Affected by Stored XSS via Attribute View Name to Electron Renderer RCE
Critical
CVE-2026-44670
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
May 8, 2026
Note Mark has a JWT Secret Weakness that allows Full Account Takeover via Token Forgery
Critical
CVE-2026-44523
was published
for
github.com/enchant97/note-mark/backend
(Go)
May 7, 2026
FileBrowser Public Share DELETE API Path Traversal Allows Unauthenticated Arbitrary File Deletion
Critical
CVE-2026-44542
was published
for
github.com/gtsteffaniak/filebrowser
(Go)
May 7, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
Critical
CVE-2026-42880
was published
for
github.com/argoproj/argo-cd/v3
(Go)
May 7, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering
Critical
CVE-2026-41050
was published
for
github.com/rancher/fleet
(Go)
May 7, 2026
Gotenberg vulnerable to unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook
Critical
CVE-2026-42596
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 7, 2026
Gotenberg has Unauthenticated RCE via ExifTool Metadata Key Injection
Critical
CVE-2026-42589
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 7, 2026
Axonflow fixed bugs by implementing multi-tenant isolation and access-control hardening
Critical
GHSA-9h64-2846-7x7f
was published
for
github.com/getaxonflow/axonflow
(Go)
May 6, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore
Critical
CVE-2026-42238
was published
for
github.com/0xJacky/nginx-ui
(Go)
May 6, 2026
DevGuard has an unauthenticated identity assertion via `X-Admin-Token` header
Critical
CVE-2026-42300
was published
for
github.com/l3montree-dev/devguard
(Go)
May 5, 2026
S3-Proxy has Security Issues in its Resource Path Matching Implementation
Critical
CVE-2026-42882
was published
for
github.com/oxyno-zeta/s3-proxy
(Go)
May 5, 2026
Pelican Web UI Affected by a Privilege Escalation Attack
Critical
CVE-2026-42571
was published
for
github.com/pelicanplatform/pelican
(Go)
May 4, 2026
ProTip!
Advisories are also available from the
GraphQL API