Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

246 advisories

Loading
dhirajranka Credited to dhirajranka and andifilhohub andifilhohub andifilhohub
wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry Moderate
CVE-2026-46438 was published for wger (pip) Oct 7, 2026
KadirArslan Credited to KadirArslan
vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features Moderate
CVE-2026-105754 was published for vllm (pip) Oct 5, 2026
KernelClint Credited to KernelClint and jperezdealgaba jperezdealgaba jperezdealgaba
KernelClint Credited to KernelClint, dhalf, and jperezdealgaba dhalf dhalf
jperezdealgaba jperezdealgaba
Trigger.dev: Cross-environment deployment cancel Moderate
GHSA-4672-hwv6-gq62 was published for trigger.dev (npm) Oct 2, 2026
CyberKareem Credited to CyberKareem
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter Moderate
CVE-2026-88978 was published for github.com/hatchet-dev/hatchet (Go) Sep 22, 2026
d3do-23 Credited to d3do-23
pirate077000 Credited to pirate077000
Unleash: Clone-feature lets a user copy a feature from a project they cannot read Moderate
CVE-2026-76910 was published for unleash-server (npm) Sep 22, 2026
Tymek Credited to Tymek
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards Moderate
CVE-2026-69190 was published for org.graylog2:graylog2-server (Maven) Sep 22, 2026
kah-ja Credited to kah-ja
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint Moderate
CVE-2026-87994 was published for open-webui (pip) Sep 10, 2026
Classic298 Credited to Classic298
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions Moderate
CVE-2026-87997 was published for open-webui (pip) Sep 10, 2026
whyiug Credited to whyiug and Classic298 Classic298 Classic298
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list` Moderate
CVE-2026-54529 was published for sqladmin (pip) Sep 9, 2026
muslimbek-0x Credited to muslimbek-0x
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath Moderate
CVE-2026-72802 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
Shirshakhtml Credited to Shirshakhtml
Sulu: Media move/update authorization bypass (IDOR) Moderate
CVE-2026-82395 was published for sulu/sulu (Composer) Sep 2, 2026
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens Moderate
CVE-2026-55867 was published for org.graylog2:graylog2-server (Maven) Aug 28, 2026
michaelddickenson Credited to michaelddickenson and sreelim sreelim sreelim
Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint Moderate
CVE-2026-55515 was published for snipe/snipe-it (Composer) Aug 28, 2026
5h1kh4r Credited to 5h1kh4r
Snipe-IT has missing object-level authorization in Kits API Moderate
CVE-2026-55478 was published for snipe/snipe-it (Composer) Aug 28, 2026
Mitchell45 Credited to Mitchell45
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment Moderate
CVE-2026-55067 was published for code.vikunja.io/api (Go) Aug 28, 2026
voraci0us Credited to voraci0us
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe Moderate
CVE-2026-54746 was published for github.com/hatchet-dev/hatchet (Go) Aug 28, 2026
sajdakabir Credited to sajdakabir
muslimbek-0x Credited to muslimbek-0x
Sakai Profile Image Deletion has an IDOR Moderate
CVE-2026-54050 was published for org.sakaiproject.profile2:profile2-api (Maven) Aug 24, 2026
geo-chen Credited to geo-chen and ottenhoff ottenhoff ottenhoff
ProTip! Advisories are also available from the GraphQL API