Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34,062 advisories

Loading
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE Critical
CVE-2026-52887 was published for @nocobase/plugin-notification-in-app-message (npm) Jul 31, 2026
kah-ja Credited to kah-ja
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow Moderate
CVE-2026-53466 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 31, 2026
Bin-infinite Credited to Bin-infinite
Savon::Model evaluates WSDL operation names as Ruby source High
CVE-2026-53510 was published for savon (RubyGems) Jul 31, 2026
connorshea Credited to connorshea
CrownKingClown Credited to CrownKingClown
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier High
CVE-2026-58263 was published for jodit (npm) Jul 31, 2026
koyokr Credited to koyokr
Jodit has prototype pollution via Jodit.configure() / ConfigMerge Moderate
CVE-2026-54756 was published for jodit (npm) Jul 31, 2026
koyokr Credited to koyokr
Thumbor has path traversal via post-validation URL decoding bypass in file_loader High
CVE-2026-53502 was published for thumbor (pip) Jul 31, 2026
q1uf3ng Credited to q1uf3ng and 0xHunSec 0xHunSec 0xHunSec
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS High
CVE-2026-53505 was published for thumbor (pip) Jul 31, 2026
m01e-40x Credited to m01e-40x
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter High
CVE-2026-53504 was published for thumbor (pip) Jul 31, 2026
geraldino2 Credited to geraldino2
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS High
CVE-2026-53503 was published for thumbor (pip) Jul 31, 2026
m01e-40x Credited to m01e-40x
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature High
CVE-2026-53501 was published for thumbor (pip) Jul 31, 2026
@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging High
CVE-2026-54737 was published for @phun-ky/defaults-deep (npm) Jul 31, 2026
supeRdaem Credited to supeRdaem
0xVijay Credited to 0xVijay
hashi-vault-js has a path traversal and query parameter injection High
CVE-2026-55100 was published for hashi-vault-js (npm) Jul 31, 2026
Sebasteuo Credited to Sebasteuo
dssrf: any users using 1.1.1.1 DNS is impacted by SSRF High
CVE-2026-54729 was published for dssrf (npm) Jul 31, 2026
thientd Credited to thientd
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests Moderate
CVE-2026-65834 was published for github.com/projectcapsule/capsule (Go) Jul 31, 2026
PhucQuan Credited to PhucQuan
Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII Moderate
CVE-2026-68501 was published for sylius/mollie-plugin (Composer) Jul 31, 2026
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook High
CVE-2026-68500 was published for sylius/mollie-plugin (Composer) Jul 31, 2026
ProTip! Advisories are also available from the GraphQL API