-
Notifications
You must be signed in to change notification settings - Fork 702
Pull requests: github/advisory-database
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[GHSA-hcjr-322h-429r] Improper Handling of URL Encoding (Hex Encoding)...
#8960
opened Aug 3, 2026 by
anderruiz
Loading…
[GHSA-m3q2-p4fw-w38m] Cross-site scripting via <NoScript> slot content in Nuxt's head components
#8958
opened Aug 3, 2026 by
sealonohana
Loading…
[GHSA-934w-87qh-qr26] Nuxt: Reflected XSS in
<NuxtLink> via unsanitised javascript: or data: URL
#8957
opened Aug 3, 2026 by
sealonohana
Loading…
[GHSA-72h4-7f42-rjh6] The Pronamic Pay plugin for WordPress is vulnerable to...
#8956
opened Aug 3, 2026 by
ictbeheer
Loading…
[GHSA-2v37-7h3g-55p8] nanoid (Nano ID) before 5.1.6 contains an infinite loop...
#8955
opened Aug 3, 2026 by
ai
Loading…
[GHSA-q4gv-pjmh-c735] Add v1.1.3 as patched version for release-1.1 backport
#8953
opened Aug 3, 2026 by
inbharajmani
Loading…
[GHSA-4c65-9gqf-4w8h] Record 0.5.10 as the fixed version for cai-framework
#8950
opened Aug 2, 2026 by
tonytonycoder11
Loading…
[GHSA-x3vf-39hj-gxr4] Record 1.87 as the fixed version for biopython
#8949
opened Aug 2, 2026 by
tonytonycoder11
Loading…
[GHSA-2fpx-xrc2-7qf3] A weakness has been identified in FedML-AI FedML up to 0...
#8948
opened Aug 2, 2026 by
mohammedix88
Loading…
[GHSA-72hv-8253-57qq] jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
#8946
opened Aug 2, 2026 by
cowtowncoder
Loading…
[GHSA-x732-6j76-qmhm] Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits
#8945
opened Aug 2, 2026 by
FROWNINGdev
Loading…
[GHSA-4vcf-q4xf-f48m] Better Auth Passkey plugin allows deletion of arbitrary passkeys by ID
#8944
opened Aug 2, 2026 by
FROWNINGdev
Loading…
[GHSA-569q-mpph-wgww] Better Auth affected by external request basePath modification DoS
#8943
opened Aug 2, 2026 by
FROWNINGdev
Loading…
[GHSA-9m9p-7p6h-xv99] FileGator accepts arbitrary Unix permission values via...
#8940
opened Aug 2, 2026 by
moizxsec
Loading…
[GHSA-qcxq-75wr-5cm8] ldap3_proto has LDAP Filter stack exhaustion
#8939
opened Aug 2, 2026 by
micolous
Loading…
[GHSA-r5fr-9gmv-jggh] scim_proto and kanidm_proto have an authenticated process abort via SCIM filter stack exhaustion
#8938
opened Aug 2, 2026 by
micolous
Loading…
[GHSA-hhpq-7wg4-36jm] CakePHP Authentication: Open redirect weakness via backslash bypass
#8937
opened Aug 2, 2026 by
aquaturtlium
Loading…
GHSA-qwww-vcr4-c8h2: split affected range — fix backported to react-router 7.18.2
#8936
opened Aug 2, 2026 by
BenjaminLimb
Loading…
[GHSA-jfv9-68m5-gjjr] mem0 server lacks authentication and authorization controls for its memory management API endpoints
#8930
opened Aug 1, 2026 by
donny-devops
Loading…
[GHSA-q9r5-6hrr-9ph7] Hugging Face smolagents: Unsafe deserialization in Remote Python Executor leads to RCE
#8929
opened Aug 1, 2026 by
donny-devops
Loading…
[GHSA-r9vw-cjf9-xh4x] ProcessWire Cross Site Request Forgery vulnerability
#8928
opened Jul 31, 2026 by
ryancramerdesign
Loading…
[GHSA-j965-2qgj-vjmq] JavaScript SDK v2 users should add validation to the region parameter value in or migrate to v3
#8926
opened Jul 31, 2026 by
dloetzke
Loading…
Previous Next
ProTip!
no:milestone will show everything without a milestone.