Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

344 advisories

Loading
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users Moderate
CVE-2026-73304 was published for @budibase/server (npm) Jul 24, 2026
offset Credited to offset
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin Moderate
CVE-2026-70599 was published for electron (npm) Aug 5, 2026
offset Credited to offset
offset Credited to offset
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output Moderate
CVE-2026-67439 was published for github.com/OliveTin/OliveTin (Go) Jul 30, 2026
offset Credited to offset
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution High
GHSA-qw6m-8fw2-2v64 was published for @budibase/server (npm) Jul 24, 2026
offset Credited to offset
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce High
CVE-2026-55575 was published for liquidjs (npm) Jul 24, 2026
offset Credited to offset
offset Credited to offset
offset Credited to offset
Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override High
CVE-2026-54351 was published for @budibase/server (npm) Jun 22, 2026
offset Credited to offset
Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE High
CVE-2026-40938 was published for github.com/tektoncd/pipeline (Go) Apr 21, 2026
offset Credited to offset, vdemeester, kodareef5, and waveywaves vdemeester vdemeester
kodareef5 kodareef5 waveywaves waveywaves
offset Credited to offset
offset Credited to offset
offset Credited to offset
FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn` Critical
CVE-2026-45262 was published for facturascripts/facturascripts (Composer) Jul 14, 2026
offset Credited to offset
Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypass Moderate
CVE-2026-52820 was published for kimai/kimai (Composer) Jul 13, 2026
offset Credited to offset
offset Credited to offset
Micronaut has unbounded `formattersCache` in `TimeConverterRegistrar` that Allows Memory Exhaustion via `Accept-Language` Header High
CVE-2026-44241 was published for io.micronaut:micronaut-context (Maven) May 6, 2026
offset Credited to offset
LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex High
CVE-2026-45617 was published for liquidjs (npm) May 27, 2026
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()` Moderate
CVE-2026-44646 was published for liquidjs (npm) May 27, 2026
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body Moderate
CVE-2026-44645 was published for liquidjs (npm) May 27, 2026
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS Moderate
CVE-2026-44644 was published for liquidjs (npm) May 27, 2026
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
ProTip! Advisories are also available from the GraphQL API