Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

111 advisories

Loading
MagicMirror: ssrf calendar .js Moderate
CVE-2026-63643 was published for magicmirror (npm) Aug 18, 2026
gabrie0x6c Credited to gabrie0x6c
Astro: Unauthenticated path override in the @astrojs/vercel ISR function Moderate
CVE-2026-73424 was published for @astrojs/vercel (npm) Jul 20, 2026
jp-soba Credited to jp-soba
The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an... Moderate Unreviewed
CVE-2026-72640 was published Aug 13, 2026
KEIJOT Credited to KEIJOT and shaked-seal shaked-seal shaked-seal
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref` Moderate
CVE-2026-54663 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor High
CVE-2026-43910 was published for io.appium:java-client (Maven) Jul 28, 2026
RobertoLuzanilla Credited to RobertoLuzanilla
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary... Critical Unreviewed
CVE-2026-42933 was published Jul 24, 2026
NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint Moderate
CVE-2026-53931 was published for nocodb (npm) Jun 17, 2026
p- Credited to p-
widavies Credited to widavies
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints Critical
CVE-2026-53513 was published for @better-auth/sso (npm) Jul 7, 2026
vaadata-poyetont Credited to vaadata-poyetont
Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities Moderate
CVE-2026-50169 was published for @angular/service-worker (npm) Jun 15, 2026
Yenya030 Credited to Yenya030, alan-agius4, JeanMeche, josephperrott, and AndrewKushnir alan-agius4 alan-agius4
JeanMeche JeanMeche josephperrott josephperrott AndrewKushnir AndrewKushnir
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode High
CVE-2026-54628 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
ProTip! Advisories are also available from the GraphQL API