Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

10,919 advisories

Loading
OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the... Moderate Unreviewed
CVE-2026-65009 was published Jul 21, 2026
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning High
GHSA-gcfj-64vw-6mp9 was published for axios (npm) Jul 20, 2026
thesmartshadow Credited to thesmartshadow
File Browser: Share API exposes the password hash and bypass token Low
CVE-2026-62684 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
je-lv Credited to je-lv and hacdias hacdias hacdias
Guzzle: Cookie Disclosure and Injection via IP-Address Domains Moderate
CVE-2026-59883 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Guzzle: Proxy-Authorization headers can be sent to origin servers Moderate
GHSA-94pj-82f3-465w was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Prompty: Arbitrary file read via file reference expansion High
CVE-2026-53598 was published for @prompty/core (npm) Jul 17, 2026
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization High
GHSA-x8mg-6r4p-87pf was published for com.arcadedb:arcadedb-server (Maven) Jul 16, 2026
ProTip! Advisories are also available from the GraphQL API