Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,034 advisories

Loading
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag High
CVE-2026-53608 was published for @apostrophecms/seo (npm) Jul 31, 2026
H3xV0rT3x Credited to H3xV0rT3x
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header Low
CVE-2026-53607 was published for apostrophe (npm) Jul 31, 2026
EchoSkorJjj Credited to EchoSkorJjj
H3xV0rT3x Credited to H3xV0rT3x
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE Critical
CVE-2026-52887 was published for @nocobase/plugin-notification-in-app-message (npm) Jul 31, 2026
kah-ja Credited to kah-ja
CrownKingClown Credited to CrownKingClown
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier High
CVE-2026-58263 was published for jodit (npm) Jul 31, 2026
koyokr Credited to koyokr
Jodit has prototype pollution via Jodit.configure() / ConfigMerge Moderate
CVE-2026-54756 was published for jodit (npm) Jul 31, 2026
koyokr Credited to koyokr
@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging High
CVE-2026-54737 was published for @phun-ky/defaults-deep (npm) Jul 31, 2026
supeRdaem Credited to supeRdaem
hashi-vault-js has a path traversal and query parameter injection High
CVE-2026-55100 was published for hashi-vault-js (npm) Jul 31, 2026
Sebasteuo Credited to Sebasteuo
dssrf: any users using 1.1.1.1 DNS is impacted by SSRF High
CVE-2026-54729 was published for dssrf (npm) Jul 31, 2026
`nx graph` dev server permissive CORS policy Moderate
CVE-2026-54753 was published for nx (npm) Jul 31, 2026
`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation High
GHSA-p7w7-4929-vpj5 was published for @dynatrace-oss/dynatrace-mcp-server (npm) Jul 31, 2026
EQSTLab Credited to EQSTLab, 232-323, and yotampe-pluto 232-323 232-323
yotampe-pluto yotampe-pluto
@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification Moderate
GHSA-xrmj-5g4g-8987 was published for @dynatrace-oss/dynatrace-mcp-server (npm) Jul 31, 2026
yotampe-pluto Credited to yotampe-pluto
@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL Moderate
GHSA-pqh8-p93p-2rx7 was published for @dynatrace-oss/dynatrace-mcp-server (npm) Jul 31, 2026
yotampe-pluto Credited to yotampe-pluto
AWS Amplify Studio UI Component Properties Has an Input Validation Issue Critical
CVE-2025-4318 was published for @aws-amplify/codegen-ui-react (npm) Jul 30, 2026
dssrf has an SSRF bypass with remove_at_symbol_in_string High
CVE-2026-54722 was published for dssrf (npm) Jul 30, 2026
HackingRepo Credited to HackingRepo and andrewmkhoury andrewmkhoury andrewmkhoury
mathlive's Lack of Escaping of HTML allows for XSS Moderate
CVE-2026-54705 was published for mathlive (npm) Jul 29, 2026
CosmicCrusader23 Credited to CosmicCrusader23
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping High
CVE-2026-11393 was published for @aws/agentcore (npm) Jul 29, 2026
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate Low
GHSA-pc2w-4mq8-32qw was published for @dynatrace-oss/dynatrace-mcp-server (npm) Jul 29, 2026
yotampe-pluto Credited to yotampe-pluto
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies High
CVE-2026-54666 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped enum string values High
CVE-2026-54664 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
ProTip! Advisories are also available from the GraphQL API