Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

623 advisories

Loading
OmniFaces: Forged combined-resource IDs and related output/push boundaries High
GHSA-fp43-vj7g-pg92 was published for org.omnifaces:omnifaces (Maven) Jul 24, 2026
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF) High
GHSA-pvcr-8mvp-w8qr was published for @budibase/server (npm) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in High
GHSA-qq9h-g4jm-xgf3 was published for better-auth (npm) Jul 24, 2026
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them Moderate
GHSA-x445-f3h2-j279 was published for @auth/core (npm) Jul 23, 2026
Nadav0077 Credited to Nadav0077
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login High
GHSA-8342-988q-86cr was published for n8n (npm) Jul 22, 2026
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability High
CVE-2026-47304 was published for System.Security.Cryptography.Xml (NuGet) Jul 20, 2026
rbhanda Credited to rbhanda
The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes... Moderate Unreviewed
CVE-2026-10724 was published Jul 20, 2026
ProTip! Advisories are also available from the GraphQL API