GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,406
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
13 advisories
Filter by severity
Directus: Unauthenticated Denial of Service via GraphQL Alias Amplification of Expensive Health Check Resolver
High
GHSA-6q22-g298-grjh
was published
for
directus
(npm)
Apr 4, 2026
Directus: TUS Upload Authorization Bypass Allows Arbitrary File Overwrite
High
CVE-2026-35412
was published
for
directus
(npm)
Apr 4, 2026
Directus: GraphQL Schema SDL Disclosure Setting
Moderate
CVE-2026-35413
was published
for
directus
(npm)
Apr 4, 2026
Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write
High
CVE-2026-35214
was published
for
@budibase/server
(npm)
Apr 4, 2026
lodash vulnerable to Code Injection via `_.template` imports key names
High
CVE-2026-4800
was published
for
lodash
(npm)
Apr 1, 2026
Parse Server has a LiveQuery protected-field guard bypass via array-like logical operator value
Moderate
CVE-2026-34595
was published
for
parse-server
(npm)
Apr 1, 2026
Parse Server has a session field immutability bypass via falsy-value guard
Moderate
CVE-2026-34574
was published
for
parse-server
(npm)
Apr 1, 2026
parse-server has GraphQL complexity validator exponential fragment traversal DoS
High
CVE-2026-34573
was published
for
parse-server
(npm)
Mar 31, 2026
parse-server has cloud function validator bypass via prototype chain traversal
Critical
CVE-2026-34532
was published
for
parse-server
(npm)
Mar 31, 2026
@appium/support has a Zip Slip arbitrary file write in its ZIP extraction
Moderate
CVE-2026-30973
was published
for
@appium/support
(npm)
Mar 11, 2026
NocoDB Vulnerable to Stored Cross-Site Scripting via Comments and Rich Text Cells
Moderate
CVE-2026-28398
was published
for
nocodb
(npm)
Mar 3, 2026
NocoDB Missing Ownership Validation in MCP Token Operations
Moderate
CVE-2026-28361
was published
for
nocodb
(npm)
Mar 2, 2026
NocoDB's Refresh Tokens Not Revoked on Password Reset
Moderate
CVE-2026-28396
was published
for
nocodb
(npm)
Mar 2, 2026
ProTip!
Advisories are also available from the
GraphQL API