Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

14 advisories

Loading
Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: scheme Moderate
CVE-2026-75510 was published for @novu/js (npm) Sep 22, 2026
kah-ja Credited to kah-ja
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards Moderate
CVE-2026-69190 was published for org.graylog2:graylog2-server (Maven) Sep 22, 2026
kah-ja Credited to kah-ja
Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text High
CVE-2026-77615 was published for org.opencastproject:opencast-engage-paella-player-7 (Maven) Sep 18, 2026
kah-ja Credited to kah-ja
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision High
CVE-2026-73293 was published for github.com/semaphoreui/semaphore (Go) Sep 3, 2026
kah-ja Credited to kah-ja
ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal Moderate
CVE-2026-63667 was published for @apostrophecms/import-export (npm) Sep 2, 2026
kah-ja Credited to kah-ja and luuhung1217 luuhung1217 luuhung1217
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter High
CVE-2026-63462 was published for unleash-server (npm) Aug 21, 2026
kah-ja Credited to kah-ja
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE Critical
CVE-2026-52887 was published for @nocobase/plugin-notification-in-app-message (npm) Jul 31, 2026
kah-ja Credited to kah-ja
SiYuan: Stored XSS in Bazaar marketplace via package README event handlers High
CVE-2026-54070 was published for github.com/siyuan-note/siyuan/kernel (Go) Jul 10, 2026
kah-ja Credited to kah-ja
Statamic Vulnerable to CSV formula injection in form submission exports Moderate
CVE-2026-54243 was published for statamic/cms (Composer) Jun 26, 2026
kah-ja Credited to kah-ja
Budibase has nonymous NoSQL operator injection via published-app query templates Critical
CVE-2026-54350 was published for @budibase/server (npm) Jun 23, 2026
kah-ja Credited to kah-ja
Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload Critical
CVE-2026-54352 was published for @budibase/server (npm) Jun 22, 2026
kah-ja Credited to kah-ja
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter High
GHSA-cc8f-fcx3-gpjr was published for surrealdb (Rust) Jun 19, 2026
kah-ja Credited to kah-ja
NocoDB: Stored Cross-Site Scripting via Form View Redirect URL High
CVE-2026-47387 was published for nocodb (npm) Jun 5, 2026
kah-ja Credited to kah-ja
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation High
CVE-2026-45738 was published for github.com/argoproj/argo-cd (Go) May 19, 2026
kah-ja Credited to kah-ja
ProTip! Advisories are also available from the GraphQL API