Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

414 advisories

Loading
xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization Moderate
CVE-2026-83610 was published for @xmldom/xmldom (npm) Sep 2, 2026
Paranoidgrinch Credited to Paranoidgrinch
fg0x0 Credited to fg0x0
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output Moderate
CVE-2026-55859 was published for org.mariadb:r2dbc-mariadb (Maven) Aug 28, 2026
fg0x0 Credited to fg0x0
PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI Low
CVE-2026-55891 was published for privatebin/privatebin (Composer) Aug 28, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team, elrido, and rugk elrido elrido
rugk rugk
eml_parser has a URL extraction bypass via HTML entities in URLs Moderate
CVE-2026-55618 was published for eml_parser (pip) Aug 25, 2026
Sebasteuo Credited to Sebasteuo
Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors High
CVE-2026-61824 was published for defuddle (npm) Aug 21, 2026
Mr-DJ Credited to Mr-DJ
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
therawdev Credited to therawdev, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
jmespath.php has CompilerRuntime code injection via unescaped function names Critical
CVE-2026-54133 was published for mtdowling/jmespath.php (Composer) Aug 18, 2026
edorian Credited to edorian
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter Moderate
CVE-2026-70609 was published for electron (npm) Aug 5, 2026
hackerman70000 Credited to hackerman70000
CentreStack before 17.4 contains a session variable injection vulnerability that allows... Moderate Unreviewed
CVE-2026-54364 was published Jul 30, 2026
ProTip! Advisories are also available from the GraphQL API