GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
445 advisories
Filter by severity
Craft CMS has a potential information disclosure vulnerability in preview tokens
Low
CVE-2026-29113
was published
for
craftcms/cms
(Composer)
Mar 10, 2026
Filament: Password validity disclosure for accounts denied panel access on login page
Low
CVE-2026-84307
was published
for
filament/filament
(Composer)
Sep 1, 2026
Craft CMS: Incorrect path validation could potentially lead to path traversal
Low
CVE-2026-72783
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI
Low
CVE-2026-55891
was published
for
privatebin/privatebin
(Composer)
Aug 28, 2026
Snipe-IT has a path traversal vulnerability via CSV import `image` field
Low
CVE-2026-55469
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions
Low
CVE-2026-54713
was published
for
cakephp/queue
(Composer)
Aug 27, 2026
OpenSTAManager has HTML Injection in modules/utenti/edit.php
Low
CVE-2026-44701
was published
for
devcode-it/openstamanager
(Composer)
Aug 26, 2026
Subrion CMS vulnerable to Cross-site Scripting
Low
CVE-2026-12202
was published
for
intelliants/subrion
(Composer)
Jun 15, 2026
Winter: Stored XSS through Backend List widget image columns
Low
GHSA-7mpf-4465-7fc2
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read
Low
CVE-2026-56394
was published
for
craftcms/cms
(Composer)
Jul 9, 2026
Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata
Low
CVE-2026-56385
was published
for
craftcms/cms
(Composer)
Mar 26, 2026
Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options
Low
CVE-2026-56393
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page
Low
CVE-2026-56381
was published
for
craftcms/cms
(Composer)
Mar 11, 2026
Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type
Low
CVE-2026-56383
was published
for
craftcms/cms
(Composer)
Feb 25, 2026
Contao: Possible path traversal in job download URIs
Low
CVE-2026-55825
was published
for
contao/contao
(Composer)
Aug 6, 2026
Contao crawler leaks auth credentials to external hosts
Low
CVE-2026-55824
was published
for
contao/contao
(Composer)
Aug 6, 2026
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS
Low
CVE-2026-52838
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
Low
CVE-2026-52841
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
Low
CVE-2026-52839
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
Low
CVE-2026-52840
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Dompdf: File existence oracle via font-face stylesheet declaration
Low
CVE-2026-55555
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
Dompdf: Chroot Validation Bypass
Low
CVE-2026-55554
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`
Low
CVE-2026-45710
was published
for
facturascripts/facturascripts
(Composer)
Jul 14, 2026
Dolibarr ERP CRM is vulnerable to Improper Authorization through its Leave Request REST API
Low
CVE-2026-10215
was published
for
dolibarr/dolibarr
(Composer)
Jun 1, 2026
Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection
Low
GHSA-gq4g-fpc9-vjfq
was published
for
web-auth/webauthn-lib
(Composer)
Jul 7, 2026
ProTip!
Advisories are also available from the
GraphQL API