GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
43
Go
3,164
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,458
Pub
12
RubyGems
991
Rust
1,184
Swift
50
Unreviewed advisories
All unreviewed
5,000+
27,184 advisories
Filter by severity
TinaCMS Vulnerable to Path Traversal Leading to Arbitrary File Read, Write and Delete
High
CVE-2026-28793
was published
for
@tinacms/cli
(npm)
Mar 12, 2026
TinaCMS CLI Dev Server Vulnerable to Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS
Critical
CVE-2026-28792
was published
for
@tinacms/cli
(npm)
Mar 12, 2026
ImageMagick: Specially crafted SVG leads to segmentation fault and generate trash files in "/tmp", possible to leverage DoS
Moderate
CVE-2023-1289
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
Black: Arbitrary file writes from unsanitized user input in cache file name
High
CVE-2026-32274
was published
for
black
(pip)
Mar 12, 2026
Hyperterse: Raw exposure of database statements in MCP search tool
Moderate
CVE-2026-31841
was published
for
hyperterse
(npm)
Mar 12, 2026
Tina: Path Traversal in Media Upload Handle
High
CVE-2026-28791
was published
for
tinacms
(npm)
Mar 12, 2026
multipart vulnerable to ReDoS in `parse_options_header()`
High
CVE-2026-28356
was published
for
multipart
(pip)
Mar 12, 2026
@tinacms/graphql has a Path Traversal issue
Moderate
CVE-2026-24125
was published
for
@tinacms/graphql
(npm)
Mar 12, 2026
Parse Server: Account takeover via operator injection in authentication data identifier
Critical
CVE-2026-32248
was published
for
parse-server
(npm)
Mar 12, 2026
Parse Server's OAuth2 adapter shares mutable state across providers via singleton instance
Critical
CVE-2026-32242
was published
for
parse-server
(npm)
Mar 12, 2026
Trix has a Stored XSS vulnerability through serialized attributes
Moderate
GHSA-qmpg-8xg6-ph5q
was published
for
action_text-trix
(RubyGems)
Mar 12, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
High
CVE-2026-32247
was published
for
graphiti-core
(pip)
Mar 12, 2026
Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint
High
CVE-2026-32246
was published
for
github.com/steveiliop56/tinyauth
(Go)
Mar 12, 2026
Tinyauth's OIDC authorization codes are not bound to client on token exchange
Moderate
CVE-2026-32245
was published
for
github.com/steveiliop56/tinyauth
(Go)
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
Moderate
GHSA-4cm8-xpfv-jv6f
was published
for
zeptoclaw
(Rust)
Mar 12, 2026
Sveltejs devalue's `devalue.parse` and `devalue.unflatten` emit objects with `__proto__` own properties
Low
GHSA-mwv9-gp5h-frr4
was published
for
devalue
(npm)
Mar 12, 2026
Parse Server has a SQL injection via query field name when using PostgreSQL
Moderate
CVE-2026-32234
was published
for
parse-server
(npm)
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
CVE-2026-32232
was published
for
zeptoclaw
(Rust)
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
High
CVE-2026-32231
was published
for
zeptoclaw
(Rust)
Mar 12, 2026
@backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets using dry-run endpoint
Moderate
CVE-2026-32237
was published
for
@backstage/plugin-scaffolder-backend
(npm)
Mar 12, 2026
@backstage/plugin-auth-backend: SSRF in experimental CIMD metadata fetch
Low
CVE-2026-32236
was published
for
@backstage/plugin-auth-backend
(npm)
Mar 12, 2026
@backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass
Moderate
CVE-2026-32235
was published
for
@backstage/plugin-auth-backend
(npm)
Mar 12, 2026
kora-lib: Token-2022 Transfer Fee Not Deducted During Payment Verification
Moderate
GHSA-725g-w329-g7qr
was published
for
kora-lib
(Rust)
Mar 12, 2026
kora-lib: Unrecognized Instruction Types Create Empty Stubs That Bypass Fee Payer Policy
Moderate
GHSA-x442-m7cc-hr92
was published
for
kora-lib
(Rust)
Mar 12, 2026
StudioCMS: REST API Missing Rank Check Allows Admin to Create Peer Admin Accounts
Moderate
CVE-2026-32106
was published
for
studiocms
(npm)
Mar 12, 2026
ProTip!
Advisories are also available from the
GraphQL API