GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,227
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,502
Pub
12
RubyGems
995
Rust
1,187
Swift
51
Unreviewed advisories
All unreviewed
5,000+
5,352 advisories
Filter by severity
Admidio is Missing Authorization on Forum Topic and Post Deletion
Moderate
CVE-2026-32818
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Admidio is Missing Authorization and CSRF Protection on Document and Folder Deletion
Critical
CVE-2026-32817
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Admidio is Missing CSRF Validation on Role Delete, Activate, and Deactivate Actions
Moderate
CVE-2026-32816
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
SimpleJWT has an Unauthenticated Denial of Service via JWE header tampering
High
CVE-2026-33204
was published
for
kelvinmo/simplejwt
(Composer)
Mar 18, 2026
Filament Unvalidated Range and Values summarizer values can be used for XSS
High
CVE-2026-33080
was published
for
filament/tables
(Composer)
Mar 18, 2026
Statamic is missing authorization check on taxonomy term creation via fieldtype
Moderate
CVE-2026-33177
was published
for
statamic/cms
(Composer)
Mar 18, 2026
Statamic has a path traversal in file dictionary fieldtype
Moderate
CVE-2026-33171
was published
for
statamic/cms
(Composer)
Mar 18, 2026
Statamic has Stored XSS via SVG Sanitization Bypass
High
CVE-2026-33172
was published
for
statamic/cms
(Composer)
Mar 18, 2026
Authentication Bypass in extension "E-Mail MFA Provider" (mfa_email)
High
CVE-2026-4208
was published
for
ralffreit/mfa-email
(Composer)
Mar 17, 2026
Broken Access Control in extension "Redirect Tab" (redirect_tab)
Low
CVE-2026-4202
was published
for
ayacoo/redirect-tab
(Composer)
Mar 17, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Moderate
CVE-2026-1323
was published
for
cpsit/typo3-mailqueue
(Composer)
Mar 18, 2026
Craft CMS Vulnerable to Stored XSS in Revision Context Menu
Moderate
CVE-2026-33051
was published
for
craftcms/cms
(Composer)
Mar 18, 2026
php-svg-lib lacks path validation on font through SVG inline styles
Moderate
CVE-2024-25117
was published
for
phenx/php-svg-lib
(Composer)
Feb 21, 2024
AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy
High
CVE-2026-33039
was published
for
wwbn/avideo
(Composer)
Mar 17, 2026
Aureus ERP vulnerable to cross-site scripting in the Chatter Message Handler
Moderate
CVE-2026-4175
was published
for
aureuserp/aureuserp
(Composer)
Mar 16, 2026
Unauthenticated Reflected XSS via innerHTML in AVideo
Moderate
CVE-2026-33035
was published
for
wwbn/avideo
(Composer)
Mar 17, 2026
AVideo affected by Session Hijacking via Unauthenticated Session ID Disclosure with Permissive CORS
High
CVE-2026-33043
was published
for
wwbn/avideo
(Composer)
Mar 17, 2026
AVideo has an Unauthenticated Password Hash Oracle via encryptPass.json.php
Moderate
CVE-2026-33041
was published
for
wwbn/avideo
(Composer)
Mar 17, 2026
AVideo affected by unauthenticated application takeover via exposed web installer on uninitialized deployments
High
CVE-2026-33038
was published
for
wwbn/avideo
(Composer)
Mar 17, 2026
Cockpit CMS has SQL Injection in MongoLite Aggregation Optimizer via toJsonExtractRaw()
High
CVE-2026-31891
was published
for
cockpit-hq/cockpit
(Composer)
Mar 17, 2026
Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()
High
CVE-2026-32267
was published
for
craftcms/cms
(Composer)
Mar 16, 2026
Shopware: Unauthenticated data extraction possible through store-api.order endpoint
High
CVE-2026-31887
was published
for
shopware/core
(Composer)
Mar 11, 2026
Bagist Cross-site Scripting vulnerability
Moderate
CVE-2024-27499
was published
for
bagisto/bagisto
(Composer)
Mar 1, 2024
simplesamlphp/xml-security: Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
High
CVE-2026-32600
was published
for
simplesamlphp/xml-security
(Composer)
Mar 13, 2026
xmlseclibs: Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
High
CVE-2026-32313
was published
for
robrichards/xmlseclibs
(Composer)
Mar 13, 2026
ProTip!
Advisories are also available from the
GraphQL API