Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,752 advisories

Loading
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions. Moderate Unreviewed
CVE-2026-65463 was published Jul 23, 2026
HO-9 Credited to HO-9
n8n: External Secrets Accessible via Workflow Expressions Outside Credentials Moderate
CVE-2026-59254 was published for n8n (npm) Jul 22, 2026
n8n: External Secrets Permission Bypass via Expression Parser Mismatch Moderate
CVE-2026-59259 was published for n8n (npm) Jul 22, 2026
YLChen-007 Credited to YLChen-007
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner High
CVE-2026-65016 was published for n8n (npm) Jul 22, 2026
ttzero25 Credited to ttzero25
Duplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner High
GHSA-mwq7-vcmc-cm4q was published for n8n (npm) Jul 22, 2026 withdrawn
Gitea LFS Deploy-Key Privilege Escalation Moderate
CVE-2026-58435 was published for code.gitea.io/gitea (Go) Jul 21, 2026
adrian-doyensec Credited to adrian-doyensec
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API Low
CVE-2026-58445 was published for code.gitea.io/gitea (Go) Jul 21, 2026
CassianStarck Credited to CassianStarck
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects High
CVE-2026-28740 was published for gitea.dev (Go) Jul 21, 2026
m2hcz Credited to m2hcz
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content Moderate
CVE-2026-57886 was published for code.gitea.io/gitea (Go) Jul 21, 2026
zulloper Credited to zulloper
Gitea: draft release attachment disclosure via missing web authorization Moderate
CVE-2026-58432 was published for code.gitea.io/gitea (Go) Jul 21, 2026
z3r0s6 Credited to z3r0s6
ProTip! Advisories are also available from the GraphQL API