GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
48
Go
3,399
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,618
Pub
13
RubyGems
1,026
Rust
1,205
Swift
52
Unreviewed advisories
All unreviewed
5,000+
28,315 advisories
Filter by severity
Parse Server has a rate limit bypass via batch request endpoint
Moderate
CVE-2026-30972
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server OAuth2 authentication adapter account takeover via identity spoofing
High
CVE-2026-30967
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server has role escalation and CLP bypass via direct `_Join` table write
Critical
CVE-2026-30966
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server vulnerable to session token exfiltration via `redirectClassNameForKey` query parameter
Critical
CVE-2026-30965
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server has a protected fields bypass via logical query operators
High
CVE-2026-30962
was published
for
parse-server
(npm)
Mar 11, 2026
Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type
High
CVE-2026-30951
was published
for
sequelize
(npm)
Mar 11, 2026
Parse Server missing audience validation in Keycloak authentication adapter
High
CVE-2026-30949
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server vulnerable to stored cross-site scripting (XSS) via SVG file upload
High
CVE-2026-30948
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server has a bypass of class-level permissions in LiveQuery
High
CVE-2026-30947
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API
High
CVE-2026-30946
was published
for
parse-server
(npm)
Mar 11, 2026
StudioCMS: IDOR — Arbitrary API Token Revocation Leading to Denial of Service
High
CVE-2026-30945
was published
for
studiocms
(npm)
Mar 11, 2026
Parse Server has a NoSQL injection via token type in password reset and email verification endpoints
High
CVE-2026-30941
was published
for
parse-server
(npm)
Mar 11, 2026
pypdf: manipulated stream length values can exhaust RAM
Moderate
CVE-2026-31826
was published
for
pypdf
(pip)
Mar 11, 2026
Sylius has a DQL Injection via API Order Filters
Moderate
CVE-2026-31825
was published
for
sylius/sylius
(Composer)
Mar 11, 2026
Sylius has a Promotion Usage Limit Bypass via Race Condition
High
CVE-2026-31824
was published
for
sylius/sylius
(Composer)
Mar 11, 2026
Sylius Vulnerable to Authenticated Stored XSS
Moderate
CVE-2026-31823
was published
for
sylius/sylius
(Composer)
Mar 11, 2026
Sylius has a XSS vulnerability in checkout login form
Moderate
CVE-2026-31822
was published
for
sylius/sylius
(Composer)
Mar 11, 2026
Sylius is Missing Authorization in API v2 Add Item Endpoint
Moderate
CVE-2026-31821
was published
for
sylius/sylius
(Composer)
Mar 11, 2026
Sylius affected by IDOR in Cart and Checkout LiveComponents
High
CVE-2026-31820
was published
for
sylius/sylius
(Composer)
Mar 11, 2026
Sylius has an Open Redirect via Referer Header
Moderate
CVE-2026-31819
was published
for
sylius/sylius
(Composer)
Mar 11, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
Moderate
CVE-2026-31815
was published
for
django-unicorn
(pip)
Mar 11, 2026
OliveTin's unsafe parsing of UniqueTrackingId can be used to write files
High
CVE-2026-31817
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
CVE-2026-31812
was published
for
quinn-proto
(Rust)
Mar 11, 2026
SiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS
Moderate
CVE-2026-31809
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 10, 2026
ProTip!
Advisories are also available from the
GraphQL API