GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,752
Maven
5,000+
npm
5,000+
NuGet
1,117
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,571
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
1,852 advisories
Filter by severity
Shopper: Missing authorization on product removal actions in CollectionProducts component
High
CVE-2026-56825
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
High
CVE-2026-56829
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: privilege escalation via improper Livewire admin component authorization
High
CVE-2026-56828
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
High
CVE-2026-56827
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration
High
CVE-2026-55416
was published
for
pimcore/pimcore
(Composer)
Sep 10, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
CVE-2026-81525
was published
for
mongodb/mongodb
(Composer)
Sep 8, 2026
Composer arbitrary command execution via a malicious package's Perforce source URL
High
CVE-2026-84361
was published
for
composer/composer
(Composer)
Sep 8, 2026
CakePHP: SmtpTransport vulnerable to CRLF header injection
High
CVE-2026-77634
was published
for
cakephp/cakephp
(Composer)
Sep 8, 2026
Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path
High
CVE-2026-84374
was published
for
maatwebsite/excel
(Composer)
Sep 8, 2026
Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge
High
CVE-2026-62669
was published
for
getgrav/grav
(Composer)
Sep 2, 2026
Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()
High
CVE-2026-64850
was published
for
getgrav/grav
(Composer)
Sep 2, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
High
CVE-2026-81892
was published
for
easycorp/easyadmin-bundle
(Composer)
Sep 2, 2026
elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)
High
CVE-2026-81891
was published
for
Studio-42/elFinder
(Composer)
Sep 2, 2026
TYPO3 CMS - Broken Access Control in Backend and Install Tool
High
CVE-2026-19418
was published
for
typo3/cms-backend
(Composer)
Sep 1, 2026
Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled
High
CVE-2026-77567
was published
for
filament/filament
(Composer)
Sep 1, 2026
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension
High
GHSA-8rr7-cvq3-gmfh
was published
for
league/commonmark
(Composer)
Sep 1, 2026
league/commonmark: Denial of service in the SmartPunct and Attributes extensions
High
GHSA-jjv6-8j6v-6j52
was published
for
league/commonmark
(Composer)
Sep 1, 2026
league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed
High
GHSA-f8fg-pg57-v4j8
was published
for
league/commonmark
(Composer)
Sep 1, 2026
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters
High
GHSA-j8pm-gj4c-rq4x
was published
for
league/commonmark
(Composer)
Sep 1, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
CVE-2026-71415
was published
for
getkirby/cms
(Composer)
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
CVE-2026-75594
was published
for
getkirby/cms
(Composer)
Aug 31, 2026
elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback
High
CVE-2026-81889
was published
for
studio-42/elfinder
(Composer)
Aug 31, 2026
Snipe-IT has an Improper Privilege Management issue
High
CVE-2026-55843
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation
High
CVE-2026-55212
was published
for
pimcore/studio-backend-bundle
(Composer)
Aug 28, 2026
Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
High
CVE-2026-55208
was published
for
pimcore/studio-backend-bundle
(Composer)
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API