GitHub Security Advisories
Open-source package ecosystem coverage across npm / PyPI / Maven / Go / RubyGems and more.
5,183 advisories tracked · showing 100
- Jun 3, 2026GHSA-28vp-6rv7-m976HighCVSS 7.1CVE-2025-15654
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
- Jun 3, 2026GHSA-g35p-px32-whv6CriticalCVSS 9.1CVE-2026-4035
A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of...
- Jun 3, 2026GHSA-qh2m-553j-rjfcHighCVSS 7.5CVE-2026-50031
ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The...
- Jun 3, 2026GHSA-mwjg-3fm6-9v84LowCVE-2026-50052
In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request...
- Jun 3, 2026GHSA-qp9q-4rh4-m8jcLowCVSS 3.1CVE-2026-10705
A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of...
- Jun 3, 2026GHSA-cr37-3vx9-9f5fMediumCVSS 7.3CVE-2026-10704
A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this...
- Jun 3, 2026GHSA-qfqj-xxqv-cxfwunknownCVE-2026-9334
Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys...
- Jun 3, 2026GHSA-4wh8-2pqj-9gw4MediumCVSS 7.3CVE-2026-10694
A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this...
- Jun 3, 2026GHSA-32gp-2g42-v9vcunknownCVE-2026-9516
Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed...
- Jun 3, 2026GHSA-f493-gq25-5c5xLowCVSS 6.3CVE-2026-10693
A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0....
- Jun 3, 2026GHSA-vm9p-5mrq-6w5fLowCVSS 6.3CVE-2026-10703
A security vulnerability has been detected in EIPStackGroup OpENer up to 2.3.0. Affected is the...
- Jun 3, 2026GHSA-5xx3-j724-wmx5LowCVSS 6.3CVE-2026-10690
A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the...
- Jun 3, 2026GHSA-q5fr-rj8r-242wMediumCVSS 4.3CVE-2026-9732
The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to...
- Jun 3, 2026GHSA-4r7r-w926-gm5jMediumCVSS 4.4CVE-2026-7421
The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all...
- Jun 3, 2026GHSA-647r-72hf-4vmhLowCVSS 4.3CVE-2026-10692
A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the...
- Jun 3, 2026GHSA-r87g-78mx-3wg4LowCVSS 4.3CVE-2026-10691
A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This...
- Jun 3, 2026GHSA-fx9q-x9g5-jgg6LowCVSS 5.5CVE-2026-10688
A vulnerability was determined in ahujasid blender-mcp up to...
- Jun 3, 2026GHSA-5hr7-6m56-f3rgLowCVSS 6.3CVE-2026-10662
A vulnerability was found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b....
- Jun 3, 2026GHSA-6rch-j2wj-8h2jLowCVE-2026-10719
Out of bounds write in openSeaChest’s --showSupportedFormats in Seagate’s openSeaChest v25.05.3...
- Jun 3, 2026GHSA-4279-q6mj-392runknownCVE-2026-27145
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS...
- Jun 3, 2026GHSA-xcxp-3whg-h83cHighCVSS 5.9CVE-2026-25861
QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm...
- Jun 3, 2026GHSA-m3jp-gxgq-rpr9HighCVE-2026-8936
Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container...
- Jun 3, 2026GHSA-gh5q-rq4h-5vjqLowCVE-2026-10717
Out of bounds write and reads in openSeaChest’s --showSCSIDefects in Seagate’s openSeaChest v25...
- Jun 3, 2026GHSA-qmm7-2j5h-mvvvMediumCVE-2026-10718
Out of bounds write in openSeaChest’s Trim/Unmap operation in Seagate’s openSeaChest v26.03.0 on...
- Jun 3, 2026GHSA-h524-452v-82p9unknownCVE-2026-42504
Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume...
- Jun 3, 2026GHSA-h3gm-q7m7-mp28unknownCVE-2026-42507
When returning errors, functions in the net/textproto package would include its input as part of...
- Jun 3, 2026GHSA-23jv-8gf4-7r88MediumCVSS 5.3CVE-2026-10650
A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function...
- Jun 3, 2026GHSA-f3qj-wr66-g552HighCVSS 7.5CVE-2024-14036
Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of service...
- Jun 3, 2026GHSA-qw79-r33f-9pvjHighCVSS 6.8CVE-2025-15653
Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local...
- Jun 3, 2026GHSA-qqw9-95ww-prfmLowCVSS 4.3CVE-2026-10661
A vulnerability has been found in ahujasid blender-mcp up to...
- Jun 3, 2026GHSA-w85v-g7rp-mcgmHighCVSS 8.2CVE-2021-4480
Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation...
- Jun 3, 2026GHSA-766g-x59x-554cHighCVSS 8.2CVE-2021-4481
Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation...
- Jun 3, 2026GHSA-6jx8-hc3v-28hrHighCVSS 8.6CVE-2022-4992
Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions VG4.1.1,...
- Jun 2, 2026GHSA-vh97-h268-rfc2MediumCVSS 7.3CVE-2026-10620
A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown...
- Jun 2, 2026GHSA-53mc-7vx2-cm58CriticalCVSS 9.8CVE-2026-5076
The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism...
- Jun 2, 2026GHSA-jjvh-j394-wqm7unknownCVE-2026-38967
CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated...
- Jun 2, 2026GHSA-ghx9-cc3j-7qrgHighCVSS 7.1CVE-2026-8036
Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary...
- Jun 2, 2026GHSA-p5cp-vqjq-6cj7unknownCVE-2026-48682
FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet...
- Jun 2, 2026GHSA-w852-7r27-32c6MediumCVSS 8.5CVE-2026-49120
Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription...
- Jun 2, 2026GHSA-pqvj-h8m2-63h6LowCVSS 4.3CVE-2026-10624
A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this...
- Jun 2, 2026GHSA-5rw2-422p-gwxrMediumCVSS 7.1CVE-2026-8035
Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to...
- Jun 2, 2026GHSA-4jf4-cfj7-xxh5MediumCVSS 6.5CVE-2026-5074
The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0'...
- Jun 2, 2026GHSA-p4qm-892g-4gm7HighCVSS 7.5CVE-2026-5073
The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order'...
- Jun 2, 2026GHSA-4849-p72j-5rw9MediumCVSS 7.3CVE-2026-10619
A vulnerability was detected in sayan365 student-management-system up to...
- Jun 2, 2026GHSA-hqhf-c4j5-73hqHighCVSS 8.8CVE-2026-1829
The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code...
- Jun 2, 2026GHSA-3vrv-754q-mq3junknownCVE-2026-10701
Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in...
- Jun 2, 2026GHSA-hmrh-mqv8-rvvrunknownCVE-2026-10702
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in...
- Jun 2, 2026GHSA-cq6h-h9c3-mq74LowCVSS 4.3CVE-2026-10616
A weakness has been identified in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is...
- Jun 2, 2026GHSA-v69f-jf53-66f6unknownCVE-2026-30586
Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain...
- Jun 2, 2026GHSA-f247-223f-rhfmHighCVSS 8.2CVE-2026-28299
SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when...
- Jun 2, 2026GHSA-g9rp-3m3m-wgj5unknownCVE-2026-33553
Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.
- Jun 2, 2026GHSA-9p7r-jmp9-7hw2MediumCVSS 4.0CVE-2019-25723
Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper input handling...
- Jun 2, 2026GHSA-fh3f-j952-25x6HighCVSS 7.6CVE-2019-25722
Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard...
- Jun 2, 2026GHSA-83wf-r644-8pqqHighCVSS 6.5CVE-2019-25721
Dräger Infinity M300 patient worn monitors with software version VG2.3.1 and earlier contain a...
- Jun 2, 2026GHSA-3rp5-97gw-r98qHighCVSS 8.2CVE-2021-4478
Dräger CC-Vision Basic before 7.5.3 and Dräger CC-Vision E-Cal before 7.2.5.0 contain an out-of...
- Jun 2, 2026GHSA-g8rg-9wq4-r9prMediumCVSS 7.3CVE-2026-10607
A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function...
- Jun 2, 2026GHSA-m4rx-8cqf-h494MediumCVSS 7.3CVE-2026-10617
A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects...
- Jun 2, 2026GHSA-87pc-67c4-x49wunknownCVE-2025-64390
A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13...
- Jun 2, 2026GHSA-744p-v485-p6h6MediumCVSS 4.0CVE-2021-4479
Dräger Atlan A350 software versions 1.00 through 1.01 contains an improper input handling...
- Jun 2, 2026GHSA-2wj9-543r-64gvMediumCVSS 7.3CVE-2026-10608
A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the...
- Jun 2, 2026GHSA-9492-c6v8-vj2hHighCVSS 6.5CVE-2019-25724
Dräger Infinity M300 patient worn monitors with software version VG2.x and earlier contain a...
- Jun 2, 2026GHSA-972f-c53g-w92cMediumCVSS 6.1CVE-2026-40713
Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control...
- Jun 2, 2026GHSA-54h6-7v4f-8wp6HighCVSS 7.8CVE-2026-40715
Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control...
- Jun 2, 2026GHSA-64c8-8qx9-25r7MediumCVSS 6.3CVE-2026-49943
CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the...
- Jun 2, 2026GHSA-3xh5-wf4g-97h5MediumCVSS 5.3CVE-2026-9590
Improper access control in the permission validation component in Devolutions Server 2026.1.19...
- Jun 2, 2026GHSA-344f-p6q5-rw6qCriticalCVSS 9.8CVE-2026-0611
Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an...
- Jun 2, 2026GHSA-7x7j-8c59-q4grMediumCVSS 5.4CVE-2026-9522
Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and...
- Jun 2, 2026GHSA-m3v4-v5gx-7wf5CriticalCVSS 9.8CVE-2026-47117
OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter...
- Jun 2, 2026GHSA-w37m-9gg4-ggmcLowCVSS 3.1CVE-2024-42206
HCL iReflection Third party vulnerable and outdated components issue was detected in the web...
- Jun 2, 2026GHSA-92jw-rf4g-rwr2HighCVE-2026-1871
TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling...
- Jun 2, 2026GHSA-6j63-xfwq-f8vjMediumCVSS 6.3CVE-2026-7299
Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names...
- Jun 2, 2026GHSA-hj75-h2wq-2xm2HighCVSS 7.8CVE-2026-24221
NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization...
- Jun 2, 2026GHSA-9rrw-qcf5-q3prMediumCVSS 7.3CVE-2026-10606
A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of...
- Jun 2, 2026GHSA-g694-w46x-9wjvHighCVSS 7.8CVE-2026-24237
NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization...
- Jun 2, 2026GHSA-6wpw-j4xp-qqv8HighCVSS 7.5CVE-2026-40780
Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP...
- Jun 2, 2026GHSA-qqrj-x4c5-376mHighCVSS 7.1CVE-2026-42654
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System...
- Jun 2, 2026GHSA-m94v-7gjf-wmxqHighCVE-2026-10047
The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the...
- Jun 2, 2026GHSA-mpc3-vg75-whwwHighCVE-2026-10046
Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the...
- Jun 2, 2026GHSA-83m8-c7v3-rw3wHighCVSS 8.8CVE-2026-10591
Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version...
- Jun 2, 2026GHSA-8pfq-65f4-r264CriticalCVSS 9.1CVE-2026-10629
SIP signaling stack in Verizon IMS (unspecified version) implements SIP signaling without IPsec...
- Jun 2, 2026GHSA-pj36-9w4r-h2r4unknownCVE-2026-35716
A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136...
- Jun 2, 2026GHSA-pxcx-h7gm-pxc9unknownCVE-2026-30650
A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask...
- Jun 2, 2026GHSA-qp5w-cf66-hcwwunknownCVE-2026-30652
A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the...
- Jun 2, 2026GHSA-ff48-whph-h93funknownCVE-2026-30649
Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to...
- Jun 2, 2026GHSA-rw3h-hf66-rvh4unknownCVE-2026-35718
A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136...
- Jun 2, 2026GHSA-6rg3-8m29-j28qunknownCVE-2026-38978
transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI...
- Jun 2, 2026GHSA-pc23-4mq4-c95vHighCVSS 7.8CVE-2026-40619
A high security vulnerability affecting Security Center main server installations has been...
- Jun 2, 2026GHSA-62q8-jg47-5wpwHighCVSS 8.8CVE-2026-7201
CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity...
- Jun 2, 2026GHSA-2h6v-g45h-32xxCriticalCVSS 10.0CVE-2026-7312
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from...
- Jun 2, 2026GHSA-28j7-fpg4-34hjHighCVSS 8.7CVE-2026-7313
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from...
- Jun 2, 2026GHSA-p3m3-2jc5-vvp6HighCVE-2026-9844
Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ...
- Jun 2, 2026GHSA-9pjg-65cc-3h57CriticalCVSS 9.8CVE-2026-7198
CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4...
- Jun 2, 2026GHSA-qhxc-r9rq-h2gwHighCVSS 8.2CVE-2026-10622
Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker...
- Jun 2, 2026GHSA-wq78-vxp9-qcffMediumCVSS 5.4CVE-2026-27351
Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly...
- Jun 2, 2026GHSA-mgw3-wpm6-x49wMediumCVSS 5.9CVE-2026-28116
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
- Jun 2, 2026GHSA-pw35-mfxv-755mHighCVSS 8.1CVE-2026-39552
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
- Jun 2, 2026GHSA-hfjv-pq6h-6ffmHighCVSS 8.1CVE-2026-39553
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
- Jun 2, 2026GHSA-w594-jcp9-58h9HighCVSS 8.1CVE-2026-39555
Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. ...
- Jun 2, 2026GHSA-7f9j-8mjp-qv5punknownCVE-2026-35717
A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136...
- Jun 2, 2026GHSA-j56r-2c4g-4gw4MediumCVSS 5.4CVE-2026-49782
Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting...