GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,653
Maven
5,000+
npm
5,000+
NuGet
928
pip
4,860
Pub
13
RubyGems
1,050
Rust
1,304
Swift
53
Unreviewed advisories
All unreviewed
5,000+
5,692 advisories
Filter by severity
WWBN AVideo has an Unauthenticated Information Disclosure via git.json.php Exposes Developer Emails and Deployed Version
Moderate
CVE-2026-40908
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
WWBN AVideo has an IDOR in Live Restreams list.json.php Exposes Other Users' Stream Keys and OAuth Tokens
Moderate
CVE-2026-40907
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
Serendipity has a Host Header Injection allows SMTP header injection via unvalidated HTTP_HOST in Message-ID email header
High
CVE-2026-39971
was published
for
s9y/serendipity
(Composer)
Apr 14, 2026
Serendipity has a Host Header Injection allows authentication cookie scoping to attacker-controlled domain in functions_config.inc.php
Moderate
CVE-2026-39963
was published
for
s9y/serendipity
(Composer)
Apr 14, 2026
October Rain has Stored XSS via SVG Filter Bypass
Moderate
CVE-2026-25133
was published
for
october/rain
(Composer)
Apr 14, 2026
October Rain has Environment Variable Exfiltration via INI Parser Interpolation
Moderate
CVE-2026-25125
was published
for
october/rain
(Composer)
Apr 14, 2026
Composer has a command injection via malicious perforce repository
High
CVE-2026-40176
was published
for
composer/composer
(Composer)
Apr 14, 2026
October CMS has Stored XSS in Event Log Mail Preview
Moderate
CVE-2026-24907
was published
for
october/system
(Composer)
Apr 14, 2026
October CMS has Stored XSS in Backend Editor Markup Classes
Moderate
CVE-2026-24906
was published
for
october/system
(Composer)
Apr 14, 2026
October Rain has a Twig Sandbox Bypass via Collection Methods
Moderate
CVE-2026-22692
was published
for
october/rain
(Composer)
Apr 14, 2026
Composer has a command injection via malicious perforce reference
High
CVE-2026-40261
was published
for
composer/composer
(Composer)
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
High
CVE-2026-38530
was published
for
krayin/laravel-crm
(Composer)
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
High
CVE-2026-38532
was published
for
krayin/laravel-crm
(Composer)
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
High
CVE-2026-38527
was published
for
krayin/laravel-crm
(Composer)
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
High
CVE-2026-38529
was published
for
krayin/laravel-crm
(Composer)
Apr 14, 2026
Kimai leaks API Token Hash via Invoice Twig Template
Low
GHSA-rh42-6rj2-xwmc
was published
for
kimai/kimai
(Composer)
Apr 14, 2026
Kimai has an Open Redirect via Unvalidated RelayState in SAML ACS Handler
Low
GHSA-3jp4-mhh4-gcgr
was published
for
kimai/kimai
(Composer)
Apr 14, 2026
graphql-php is affected by a Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged validation
Moderate
CVE-2026-40476
was published
for
webonyx/graphql-php
(Composer)
Apr 14, 2026
Craft Commerce has an unauthenticated information disclosure that can leak some customer order data on anonymous payments
Low
CVE-2026-32270
was published
for
craftcms/commerce
(Composer)
Apr 14, 2026
Craft Commerce has a SQL Injection can lead to Remote Code Execution via TotalRevenue Widget
High
CVE-2026-32271
was published
for
craftcms/commerce
(Composer)
Apr 14, 2026
Craft Commerce hasVariant/hasProduct Blind SQL Injection
High
CVE-2026-32272
was published
for
craftcms/commerce
(Composer)
Apr 14, 2026
LibreNMS affected by an authenticated Cross-site Scripting vulnerability on the showconfig page
Moderate
CVE-2026-2728
was published
for
librenms/librenms
(Composer)
Apr 13, 2026
Duplicate Advisory: LibreNMS is Vulnerable to Remote Code Execution by Arbitrary File Write
High
GHSA-7549-ggpq-22w8
was published
for
librenms/librenms
(Composer)
Apr 13, 2026
•
withdrawn
Dolibarr has SQL injection vulnerability in the rowid parameter of the admin dict.php
High
CVE-2019-25710
was published
for
dolibarr/dolibarr
(Composer)
Apr 12, 2026
rhukster/dom-sanitizer: SVG <style> tag allows CSS injection via unfiltered url() and @import directives
Moderate
CVE-2026-40301
was published
for
rhukster/dom-sanitizer
(Composer)
Apr 10, 2026
ProTip!
Advisories are also available from the
GraphQL API