GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,270
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,517
Pub
12
RubyGems
998
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
27,557 advisories
Filter by severity
Parse Server's MFA recovery codes not consumed after use
High
CVE-2026-31875
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server has a protected fields bypass via dot-notation in query and sort
High
CVE-2026-31872
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server vulnerable to SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQL
Critical
CVE-2026-31871
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server vulnerable to stored XSS via file upload of HTML-renderable file types
Moderate
CVE-2026-31868
was published
for
parse-server
(npm)
Mar 11, 2026
flagd Vulnerable to Allocation of Resources Without Limits or Throttling
High
CVE-2026-31866
was published
for
github.com/open-feature/flagd/flagd
(Go)
Mar 11, 2026
Terraform Provider for SendGrid: TLS Session Resumption Bypasses Certificate Authority Trust Store Modifications in Go
Critical
GHSA-j443-wcqq-xprh
was published
for
github.com/arslanbekov/terraform-provider-sendgrid
(Go)
Mar 11, 2026
Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })
Moderate
GHSA-v8w9-8mx6-g223
was published
for
hono
(npm)
Mar 11, 2026
actix-web-lab has host header poisoning in redirect middleware can generate attacker-controlled absolute redirects
Moderate
GHSA-vhj5-x93p-67jw
was published
for
actix-web-lab
(Rust)
Mar 11, 2026
CraftCMS's `ElementSearchController` Affected by Blind SQL Injection
High
CVE-2026-31858
was published
for
craftcms/cms
(Composer)
Mar 11, 2026
Parse Server vulnerable to SQL injection via `Increment` operation on nested object field in PostgreSQL
Critical
CVE-2026-31856
was published
for
parse-server
(npm)
Mar 11, 2026
CraftCMS vulnerable to reflective XSS via incomplete return URL sanitization
Moderate
CVE-2026-31859
was published
for
craftcms/cms
(Composer)
Mar 11, 2026
@siteboon/claude-code-ui is Vulnerable to Command Injection via Multiple Parameters
Critical
CVE-2026-31862
was published
for
@siteboon/claudecodeui
(npm)
Mar 11, 2026
Umbraco Backoffice API Allows Unauthorized Modification of Domain Data
Moderate
CVE-2026-31832
was published
for
Umbraco.Cms
(NuGet)
Mar 11, 2026
sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digest
High
CVE-2026-31830
was published
for
sigstore
(RubyGems)
Mar 11, 2026
Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access
High
CVE-2026-31829
was published
for
flowise
(npm)
Mar 11, 2026
Parse Server vulnerable to LDAP injection via unsanitized user input in DN and group filter construction
Moderate
CVE-2026-31828
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server: Classes `_GraphQLConfig` and `_Audience` master key bypass via generic class routes
High
CVE-2026-31800
was published
for
parse-server
(npm)
Mar 11, 2026
@appium/support has a Zip Slip arbitrary file write in its ZIP extraction
Moderate
CVE-2026-30973
was published
for
@appium/support
(npm)
Mar 11, 2026
Parse Server has a rate limit bypass via batch request endpoint
Moderate
CVE-2026-30972
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server OAuth2 authentication adapter account takeover via identity spoofing
High
CVE-2026-30967
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server has role escalation and CLP bypass via direct `_Join` table write
Critical
CVE-2026-30966
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server vulnerable to session token exfiltration via `redirectClassNameForKey` query parameter
Critical
CVE-2026-30965
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server has a protected fields bypass via logical query operators
High
CVE-2026-30962
was published
for
parse-server
(npm)
Mar 11, 2026
Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type
High
CVE-2026-30951
was published
for
sequelize
(npm)
Mar 11, 2026
Parse Server missing audience validation in Keycloak authentication adapter
High
CVE-2026-30949
was published
for
parse-server
(npm)
Mar 11, 2026
ProTip!
Advisories are also available from the
GraphQL API