Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

405 advisories

Loading
Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors High
CVE-2026-61824 was published for defuddle (npm) Aug 21, 2026
Mr-DJ Credited to Mr-DJ
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
therawdev Credited to therawdev, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
jmespath.php has CompilerRuntime code injection via unescaped function names Critical
CVE-2026-54133 was published for mtdowling/jmespath.php (Composer) Aug 18, 2026
edorian Credited to edorian
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter Moderate
CVE-2026-70609 was published for electron (npm) Aug 5, 2026
hackerman70000 Credited to hackerman70000
CentreStack before 17.4 contains a session variable injection vulnerability that allows... Moderate Unreviewed
CVE-2026-54364 was published Jul 30, 2026
mathlive's Lack of Escaping of HTML allows for XSS Moderate
CVE-2026-54705 was published for mathlive (npm) Jul 29, 2026
CosmicCrusader23 Credited to CosmicCrusader23
Shescape: Home-directory disclosure in assignment context on Unix with Dash Moderate
CVE-2026-73411 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797 Moderate
GHSA-hc76-7mpc-qjqh was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) High
CVE-2026-73417 was published for jupyterlab (pip) Jul 22, 2026
de3erve-hunter Credited to de3erve-hunter, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
yorukot Credited to yorukot
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility Moderate
CVE-2026-59895 was published for hono (npm) Jul 21, 2026
a-tt-om Credited to a-tt-om and teebow1e teebow1e teebow1e
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands Low
CVE-2026-59727 was published for astro (npm) Jul 20, 2026
jlgore Credited to jlgore
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability Moderate
CVE-2026-50659 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Jul 20, 2026
ProTip! Advisories are also available from the GraphQL API