Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

743 advisories

Loading
n8n: Google Service Account Private Key Exposed in JWT Header Moderate
CVE-2026-65599 was published for n8n (npm) Jul 22, 2026
sladkani Credited to sladkani
Duplicate Advisory: Google Service Account Private Key Exposed in JWT Header Moderate
GHSA-mhvh-gwhr-76pw was published for n8n (npm) Jul 22, 2026 withdrawn
Malayke Credited to Malayke
nebula-mesh: Operator session tokens stored in plaintext in the database High
CVE-2026-53603 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
ActiveMQ Artemis has Insufficiently Protected Credentials Moderate
CVE-2020-10727 was published for org.apache.activemq:artemis-commons (Maven) May 24, 2022
nginx-ui Backup Restore Allows Tampering with Encrypted Backups Critical
CVE-2026-33026 was published for github.com/0xJacky/Nginx-UI (Go) Mar 30, 2026
dapickle Credited to dapickle and cookesan cookesan cookesan
In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the... Moderate Unreviewed
CVE-2023-25263 was published Mar 27, 2023
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted Moderate
CVE-2026-50267 was published for Steeltoe.Configuration.Abstractions (NuGet) Jul 2, 2026
Flowise: Unauthenticated Information Disclosure of OAuth Secrets (Cleartext) via GET Request Moderate
CVE-2026-56270 was published for flowise (npm) Apr 16, 2026
berkdedekarginoglu Credited to berkdedekarginoglu
nebula-mesh's stores enrollment tokens unhashed in SQLite Moderate
GHSA-ghmh-jhmj-wcmf was published for github.com/juev/nebula-mesh (Go) Jun 22, 2026
ak2k Credited to ak2k
Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets Moderate
CVE-2026-55885 was published for getgrav/grav (Composer) Jun 18, 2026
nicl4ssic Credited to nicl4ssic
ProTip! Advisories are also available from the GraphQL API