Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

15 advisories

Loading
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
Wagtail: Pages translations can be created without page permissions when using simple_translation Moderate
CVE-2026-54262 was published for wagtail (pip) Aug 20, 2026
devansh3008 Credited to devansh3008, zerolab, gasman, and iaohkut-from-NightWolf-Team zerolab zerolab
gasman gasman iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect Low
CVE-2026-59730 was published for @astrojs/node (npm) Jul 20, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
@astrojs/rss: XML Injection via Unescaped RSS Feed Fields Moderate
CVE-2026-59728 was published for @astrojs/rss (npm) Jul 20, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect Low
GHSA-gx4c-2hqx-cw2r was published for github.com/rclone/rclone (Go) Aug 5, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team and ncw ncw ncw
fast-uri vulnerable to host confusion via backslash authority introducer High
CVE-2026-18446 was published for fast-uri (npm) Aug 3, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
SvelteKit: Prototype pollution in file input deletion path in remote-function forms Moderate
GHSA-866w-xmhq-wj7x was published for @sveltejs/kit (npm) Jul 24, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team and dummdidumm dummdidumm dummdidumm
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
motionEye's missing authentication on ActionHandler allows unauthenticated camera action execution Moderate
CVE-2026-55863 was published for motioneye (pip) Jun 23, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team, MichaIng, zagrim, Marijn0, and C4spr0x1A MichaIng MichaIng
zagrim zagrim Marijn0 Marijn0 C4spr0x1A C4spr0x1A
motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read High
CVE-2026-55488 was published for motioneye (pip) Jun 23, 2026
pizza-power Credited to pizza-power, sermikr0, C4spr0x1A, MichaIng, and iaohkut-from-NightWolf-Team sermikr0 sermikr0
C4spr0x1A C4spr0x1A MichaIng MichaIng iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team
ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components Low
CVE-2026-55671 was published for github.com/zitadel/zitadel (Go) Jun 18, 2026
wooseokdotkim Credited to wooseokdotkim, IAM-marco, livio-a, 0xBassia, iaohkut-from-NightWolf-Team, dungNHVhust, sondt99, DavidCarliez, tikket1, Wernerina, morimori-dev, and vamsik2k5 IAM-marco IAM-marco
livio-a livio-a 0xBassia 0xBassia iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team dungNHVhust dungNHVhust sondt99 sondt99 DavidCarliez DavidCarliez tikket1 tikket1 Wernerina Wernerina morimori-dev morimori-dev vamsik2k5 vamsik2k5
File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope Moderate
CVE-2026-54094 was published for github.com/filebrowser/filebrowser (Go) Jun 12, 2026
DavidCarliez Credited to DavidCarliez, hacdias, m2hcz, and iaohkut-from-NightWolf-Team hacdias hacdias
m2hcz m2hcz iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team
Firefly II has Stored XSS in Audit Log Entry view via piggy bank name (ale.twig) Moderate
GHSA-6jq6-x4cx-qvcm was published for grumpydictator/firefly-iii (Composer) Jun 12, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
ProTip! Advisories are also available from the GraphQL API