Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

599 advisories

Loading
berkdedekarginoglu Credited to berkdedekarginoglu
Aviral2642 Credited to Aviral2642
Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration High
CVE-2026-69250 was published for flowise (npm) Aug 4, 2026
b-hermes Credited to b-hermes
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook High
CVE-2026-68500 was published for sylius/mollie-plugin (Composer) Jul 31, 2026
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions. High Unreviewed
CVE-2026-59546 was published Jul 27, 2026
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own High
GHSA-rm67-g9ch-vxff was published for poweradmin/poweradmin (Composer) Jul 24, 2026
SaifSalah Credited to SaifSalah
themudhaxk Credited to themudhaxk and Ardeey-code Ardeey-code Ardeey-code
waiveyk Credited to waiveyk and Classic298 Classic298 Classic298
ProTip! Advisories are also available from the GraphQL API