Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

664 advisories

Loading
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy High
CVE-2026-72809 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
Shirshakhtml Credited to Shirshakhtml
Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions. Moderate Unreviewed
CVE-2026-84766 was published Sep 3, 2026
Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions. Moderate Unreviewed
CVE-2026-84849 was published Sep 3, 2026
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) Moderate
CVE-2026-73840 was published for github.com/openchoreo/openchoreo (Go) Sep 2, 2026
ihopenre-eng Credited to ihopenre-eng
Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions. High Unreviewed
CVE-2026-82228 was published Aug 31, 2026
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF High
CVE-2026-55641 was published for 9router (npm) Aug 28, 2026
EchoSkorJjj Credited to EchoSkorJjj
phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers High
CVE-2026-55584 was published for phpsysinfo/phpsysinfo (Composer) Aug 28, 2026
mirackayikci Credited to mirackayikci
AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching Critical
CVE-2026-49757 was published for ash_authentication (Erlang) Aug 25, 2026
jimsynz Credited to jimsynz, maennchen, and jarlah maennchen maennchen
jarlah jarlah
ProTip! Advisories are also available from the GraphQL API