GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
45
GitHub Actions
47
Go
3,309
Maven
5,000+
npm
5,000+
NuGet
876
pip
4,531
Pub
12
RubyGems
1,009
Rust
1,195
Swift
51
Unreviewed advisories
All unreviewed
5,000+
5,428 advisories
Filter by severity
Bagisto Cross-Site Request Forgery vulnerability
High
CVE-2023-36237
was published
for
bagisto/bagisto
(Composer)
Feb 27, 2024
Deserialization of Untrusted Data in Torrentpier
Critical
CVE-2024-1651
was published
for
torrentpier/torrentpier
(Composer)
Feb 20, 2024
Saloon has a Fixture Name Path Traversal Vulnerability
Moderate
CVE-2026-33183
was published
for
saloonphp/saloon
(Composer)
Mar 25, 2026
Saloon is vulnerable to SSRF and credential leakage via absolute URL in endpoint overriding base URL
Moderate
CVE-2026-33182
was published
for
saloonphp/saloon
(Composer)
Mar 25, 2026
AVideo is Vulnerable to SQL Injection through Subscribe Endpoint via Unsanitized user_id Parameter
High
CVE-2026-33723
was published
for
wwbn/avideo
(Composer)
Mar 25, 2026
AVideo: Unauthenticated CDN Configuration Takeover via Empty Default Key Bypass and Mass-Assignment
High
CVE-2026-33719
was published
for
wwbn/avideo
(Composer)
Mar 25, 2026
AVideo: Remote Code Execution via PHP Temp File in Encoder downloadURL
High
CVE-2026-33717
was published
for
wwbn/avideo
(Composer)
Mar 25, 2026
AVideo Allows Unauthenticated Live Stream Control via Token Verification URL Override in control.json.php
Critical
CVE-2026-33716
was published
for
wwbn/avideo
(Composer)
Mar 25, 2026
Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion
High
GHSA-p2gh-cfq4-4wjc
was published
for
google/protobuf
(Composer)
Mar 25, 2026
Craft CMS has an authorization bypass which allows any control panel user to move entries without permissions
Moderate
CVE-2026-33162
was published
for
craftcms/cms
(Composer)
Mar 24, 2026
Craft CMS' anonymous "assets/image-editor" calls return private asset editor metadata to unauthorized users
Low
CVE-2026-33161
was published
for
craftcms/cms
(Composer)
Mar 24, 2026
Craft CMS may expose private assets through anonymous "generate transform" calls via transform URL
Low
CVE-2026-33160
was published
for
craftcms/cms
(Composer)
Mar 24, 2026
Craft CMS: Unauthenticated Users Can Perform Restricted Project Config Sync Operations
Moderate
CVE-2026-33159
was published
for
craftcms/cms
(Composer)
Mar 24, 2026
Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)
Moderate
CVE-2026-33158
was published
for
craftcms/cms
(Composer)
Mar 24, 2026
Craft CMS is Vulnerable to Authenticated Remote Code Execution via Malicious Attached Behavior
High
CVE-2026-33157
was published
for
craftcms/cms
(Composer)
Mar 24, 2026
Statamic vulnerable to remote code execution via Antlers-enabled control panel inputs
High
CVE-2026-28425
was published
for
statamic/cms
(Composer)
Mar 1, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
High
CVE-2026-32300
was published
for
opensource-workshop/connect-cms
(Composer)
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
High
CVE-2026-32299
was published
for
opensource-workshop/connect-cms
(Composer)
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
Moderate
CVE-2026-32279
was published
for
opensource-workshop/connect-cms
(Composer)
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
High
CVE-2026-32278
was published
for
opensource-workshop/connect-cms
(Composer)
Mar 23, 2026
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
High
CVE-2026-32277
was published
for
opensource-workshop/connect-cms
(Composer)
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
High
CVE-2026-32276
was published
for
opensource-workshop/connect-cms
(Composer)
Mar 23, 2026
AVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP)
High
CVE-2026-33513
was published
for
wwbn/avideo
(Composer)
Mar 20, 2026
MantisBT is vulnerable to authentication bypass through the SOAP API on MySQL
Critical
CVE-2026-30849
was published
for
mantisbt/mantisbt
(Composer)
Mar 23, 2026
AVideo Affected by CSRF on Plugin Import Endpoint Enables Unauthenticated Remote Code Execution via Malicious Plugin Upload
High
CVE-2026-33507
was published
for
wwbn/avideo
(Composer)
Mar 20, 2026
ProTip!
Advisories are also available from the
GraphQL API