Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2 advisories

Loading
FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider Critical
CVE-2026-92161 was published for fof/oauth (Composer) Sep 25, 2026
faran1512 Credited to faran1512
Semaphore U: OS Command Injection Critical
CVE-2026-73294 was published for github.com/semaphoreui/semaphore (Go) Sep 8, 2026
faran1512 Credited to faran1512
ProTip! Advisories are also available from the GraphQL API