GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,212
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,494
Pub
12
RubyGems
995
Rust
1,186
Swift
51
Unreviewed advisories
All unreviewed
5,000+
5,347 advisories
Filter by severity
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Moderate
CVE-2026-1323
was published
for
cpsit/typo3-mailqueue
(Composer)
Mar 18, 2026
Craft CMS Vulnerable to Stored XSS in Revision Context Menu
Moderate
CVE-2026-33051
was published
for
craftcms/cms
(Composer)
Mar 18, 2026
AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy
High
CVE-2026-33039
was published
for
wwbn/avideo
(Composer)
Mar 17, 2026
Unauthenticated Reflected XSS via innerHTML in AVideo
Moderate
CVE-2026-33035
was published
for
wwbn/avideo
(Composer)
Mar 17, 2026
AVideo affected by Session Hijacking via Unauthenticated Session ID Disclosure with Permissive CORS
High
CVE-2026-33043
was published
for
wwbn/avideo
(Composer)
Mar 17, 2026
AVideo has an Unauthenticated Password Hash Oracle via encryptPass.json.php
Moderate
CVE-2026-33041
was published
for
wwbn/avideo
(Composer)
Mar 17, 2026
AVideo affected by unauthenticated application takeover via exposed web installer on uninitialized deployments
High
CVE-2026-33038
was published
for
wwbn/avideo
(Composer)
Mar 17, 2026
Cockpit CMS has SQL Injection in MongoLite Aggregation Optimizer via toJsonExtractRaw()
High
CVE-2026-31891
was published
for
cockpit-hq/cockpit
(Composer)
Mar 17, 2026
Authentication Bypass in extension "E-Mail MFA Provider" (mfa_email)
High
CVE-2026-4208
was published
for
ralffreit/mfa-email
(Composer)
Mar 17, 2026
Broken Access Control in extension "Redirect Tab" (redirect_tab)
Low
CVE-2026-4202
was published
for
ayacoo/redirect-tab
(Composer)
Mar 17, 2026
Admidio has a Second-Order SQL Injection via List Configuration (lsc_special_field, lsc_sort, lsc_filter)
High
CVE-2026-32813
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Admidio is Missing Authorization on Forum Topic and Post Deletion
Moderate
GHSA-g375-5wmp-xr78
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Admidio has an HTMLPurifier Bypass in eCard Message Allows HTML Email Injection
Moderate
CVE-2026-32757
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Admidio is Missing Authorization and CSRF Protection on Document and Folder Deletion
Critical
GHSA-rmpj-3x5m-9m5f
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Admidio Vulnerable to SSRF and Local File Read via Unrestricted URL Fetch in SSO Metadata Endpoint
Moderate
CVE-2026-32812
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Admidio is Missing CSRF Protection on Role Membership Date Changes
Moderate
CVE-2026-32755
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Admidio is Missing CSRF Validation on Role Delete, Activate, and Deactivate Actions
Moderate
GHSA-wwg8-6ffr-h4q2
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
File Upload(RCE) Vulnerability in admidio
High
CVE-2026-32756
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Azure Blob Storage for Craft CMS Potential Sensitive Information Disclosure vulnerability
High
CVE-2026-32268
was published
for
craftcms/azure-blob
(Composer)
Mar 16, 2026
Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()
High
CVE-2026-32267
was published
for
craftcms/cms
(Composer)
Mar 16, 2026
Google Cloud Storage for Craft CMS has an Information Disclosure Vulnerability
Low
CVE-2026-32266
was published
for
craftcms/google-cloud
(Composer)
Mar 16, 2026
Amazon S3 for Craft CMS has an Information Disclosure vulnerability
Moderate
CVE-2026-32265
was published
for
craftcms/aws-s3
(Composer)
Mar 16, 2026
Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
High
CVE-2026-32264
was published
for
craftcms/cms
(Composer)
Mar 16, 2026
Craft CMS vulnerable to behavior injection RCE via EntryTypesController
High
CVE-2026-32263
was published
for
craftcms/cms
(Composer)
Mar 16, 2026
Craft CMS has a Path Traversal Vulnerability in AssetsController
Moderate
CVE-2026-32262
was published
for
craftcms/cms
(Composer)
Mar 16, 2026
ProTip!
Advisories are also available from the
GraphQL API