GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,479
Maven
5,000+
npm
5,000+
NuGet
886
pip
4,740
Pub
13
RubyGems
1,031
Rust
1,225
Swift
53
Unreviewed advisories
All unreviewed
5,000+
61 advisories
Filter by severity
PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint
High
GHSA-x462-jjpc-q4q4
was published
for
praisonaiagents
(pip)
Apr 10, 2026
CORS misconfiguration in CoolerControl/coolercontrold <4.0.0 allows unauthenticated remote...
Moderate
Unreviewed
CVE-2026-5302
was published
Apr 8, 2026
SiYuan is Vulnerable to Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection
Critical
CVE-2026-34449
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 31, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface
Moderate
CVE-2026-34227
was published
for
github.com/bishopfox/sliver
(Go)
Mar 31, 2026
When the internal webserver is enabled (default is disabled), an attacker might be able to trick...
Low
Unreviewed
CVE-2026-0397
was published
Mar 31, 2026
MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)
Moderate
CVE-2026-34237
was published
for
io.modelcontextprotocol.sdk:mcp-core
(Maven)
Mar 30, 2026
Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard
High
CVE-2026-33533
was published
for
Glances
(pip)
Mar 30, 2026
HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS...
Low
Unreviewed
CVE-2025-55274
was published
Mar 26, 2026
qui CORS Misconfiguration: Arbitrary Origins Trusted
Critical
CVE-2026-30924
was published
for
github.com/autobrr/qui
(Go)
Mar 19, 2026
AVideo affected by Session Hijacking via Unauthenticated Session ID Disclosure with Permissive CORS
High
CVE-2026-33043
was published
for
wwbn/avideo
(Composer)
Mar 17, 2026
Glances's Default CORS Configuration Allows Cross-Origin Credential Theft
High
CVE-2026-32610
was published
for
Glances
(pip)
Mar 16, 2026
TinaCMS CLI Dev Server Vulnerable to Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS
Critical
CVE-2026-28792
was published
for
@tinacms/cli
(npm)
Mar 12, 2026
mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft
High
CVE-2026-33010
was published
for
mcp-memory-service
(pip)
Mar 7, 2026
A permissive web security configuration may allow cross-origin restrictions enforced by modern...
Low
Unreviewed
CVE-2025-9292
was published
Feb 13, 2026
Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins
High
CVE-2026-25478
was published
for
litestar
(pip)
Feb 9, 2026
Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js...
Moderate
Unreviewed
CVE-2025-13984
was published
Jan 28, 2026
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) implement an...
High
Unreviewed
CVE-2026-24435
was published
Jan 26, 2026
OpenCode's Unauthenticated HTTP Server Allows Arbitrary Command Execution
High
CVE-2026-22812
was published
for
opencode-ai
(npm)
Jan 13, 2026
A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker...
Moderate
Unreviewed
CVE-2025-55462
was published
Jan 13, 2026
Same-origin policy bypass in the DOM: Workers component. This vulnerability affects Firefox < 145...
High
Unreviewed
CVE-2025-13019
was published
Nov 11, 2025
Same-origin policy bypass in the DOM: Notifications component. This vulnerability affects Firefox...
High
Unreviewed
CVE-2025-13017
was published
Nov 11, 2025
The issue was addressed with improved checks. This issue is fixed in Safari 26.1, visionOS 26.1,...
High
Unreviewed
CVE-2025-43480
was published
Nov 4, 2025
The issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1,...
Moderate
Unreviewed
CVE-2025-43392
was published
Nov 4, 2025
Strapi core vulnerable to sensitive data exposure via CORS misconfiguration
High
CVE-2025-53092
was published
for
@strapi/core
(npm)
Oct 16, 2025
IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains...
Moderate
Unreviewed
CVE-2023-37401
was published
Oct 9, 2025
ProTip!
Advisories are also available from the
GraphQL API