GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,627
Maven
5,000+
npm
5,000+
NuGet
928
pip
4,848
Pub
13
RubyGems
1,045
Rust
1,301
Swift
53
Unreviewed advisories
All unreviewed
5,000+
29,566 advisories
Filter by severity
Admidio vulnerable to reflected XSS in msg_window.php via Square Bracket to HTML Tag Conversion
Moderate
CVE-2026-41661
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio has Inverted 2FA Reset Authorization Check that Lets Group Leaders Strip Admin TOTP
High
CVE-2026-41660
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio Leaks Hidden Profile Field Values via Blind Search Oracle in Member Assignment
Low
CVE-2026-41659
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio's Missing Authorization on Inventory Module Destructive Endpoints Allows Any Authenticated User to Delete Items
Moderate
CVE-2026-41658
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio Exposes Cross-Organization Member Data via Permission Check Mismatch in contacts_data.php
Moderate
CVE-2026-41657
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio has Path Traversal via Unvalidated `name` Parameter in Document Add Mode that Enables Arbitrary Server File Read
Moderate
CVE-2026-41656
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio has Path Traversal in ECard Preview that Allows Reading Arbitrary Server Files Including Database Credentials
Moderate
CVE-2026-41655
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
OpenClaw: Webchat audio embedding could read local files without local-root containment
Moderate
GHSA-gfg9-5357-hv4c
was published
for
openclaw
(npm)
Apr 29, 2026
OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners
Moderate
GHSA-c28g-vh7m-fm7v
was published
for
openclaw
(npm)
Apr 29, 2026
n8n has XML Node Prototype Pollution that to RCE
Critical
CVE-2026-42232
was published
for
n8n
(npm)
Apr 29, 2026
n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE
Critical
CVE-2026-42231
was published
for
n8n
(npm)
Apr 29, 2026
n8n Vulnerable to XSS via MCP OAuth client
High
CVE-2026-42235
was published
for
n8n
(npm)
Apr 29, 2026
n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay
High
CVE-2026-42226
was published
for
n8n
(npm)
Apr 29, 2026
n8n has a Python Task Runner Sandbox Escape Vulnerability
High
CVE-2026-42234
was published
for
n8n
(npm)
Apr 29, 2026
n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure
Moderate
CVE-2026-42227
was published
for
n8n
(npm)
Apr 29, 2026
n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration
High
CVE-2026-42236
was published
for
n8n
(npm)
Apr 29, 2026
n8n Vulnerable to Hijacking of Unauthenticated Chat Execution
Moderate
CVE-2026-42228
was published
for
n8n
(npm)
Apr 29, 2026
n8n has SQL Injection in SeaTable Node
Moderate
CVE-2026-42229
was published
for
n8n
(npm)
Apr 29, 2026
n8n has Open Redirect in MCP OAuth Consent Flow
Moderate
CVE-2026-42230
was published
for
n8n
(npm)
Apr 29, 2026
n8n has SQL Injection in Oracle Database Node via Limit Field
Moderate
CVE-2026-42233
was published
for
n8n
(npm)
Apr 29, 2026
n8n has SQL Injection in Snowflake and MySQL Nodes
Moderate
CVE-2026-42237
was published
for
n8n
(npm)
Apr 29, 2026
ipl/web is vulnerable to reflected XSS by malformed search requests
High
CVE-2026-42224
was published
for
ipl/web
(Composer)
Apr 29, 2026
appsmith has SQL Injection in FilterDataService via Unsafe DROP TABLE Execution
High
GHSA-h8cj-hpmg-636v
was published
for
com.appsmith:interfaces
(Maven)
Apr 29, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services
High
GHSA-wr32-99hh-6f35
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Apr 29, 2026
OpenID Connect nonce generated but never validated — ID token replay attack
Moderate
CVE-2026-42206
was published
for
roadiz/openid
(Composer)
Apr 29, 2026
ProTip!
Advisories are also available from the
GraphQL API