Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,417 advisories

Loading
Snipe-IT has an Improper Privilege Management issue High
CVE-2026-55843 was published for snipe/snipe-it (Composer) Aug 28, 2026
mattimustang Credited to mattimustang
silverstripe/versioned has XSS in archive admin restore Moderate
CVE-2026-55779 was published for silverstripe/versioned (Composer) Aug 28, 2026
PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI Low
CVE-2026-55891 was published for privatebin/privatebin (Composer) Aug 28, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team, elrido, and rugk elrido elrido
rugk rugk
EvidentObscurity Credited to EvidentObscurity, rugk, and elrido rugk rugk
elrido elrido
Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name Critical
CVE-2026-55634 was published for pimcore/pimcore (Composer) Aug 28, 2026
Yanchon918s Credited to Yanchon918s
tonghuaroot Credited to tonghuaroot
Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation High
CVE-2026-55212 was published for pimcore/studio-backend-bundle (Composer) Aug 28, 2026
dhairya7760 Credited to dhairya7760
byteoverride Credited to byteoverride
Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass High
CVE-2026-55207 was published for pimcore/studio-backend-bundle (Composer) Aug 28, 2026
byteoverride Credited to byteoverride
phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers High
CVE-2026-55584 was published for phpsysinfo/phpsysinfo (Composer) Aug 28, 2026
mirackayikci Credited to mirackayikci
Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update High
CVE-2026-55516 was published for snipe/snipe-it (Composer) Aug 28, 2026
5h1kh4r Credited to 5h1kh4r and builtbybrayden builtbybrayden builtbybrayden
Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint Moderate
CVE-2026-55515 was published for snipe/snipe-it (Composer) Aug 28, 2026
5h1kh4r Credited to 5h1kh4r
Snipe-IT has CSS Injection via `header_color` Setting Moderate
CVE-2026-55481 was published for snipe/snipe-it (Composer) Aug 28, 2026
ZeroXJacks Credited to ZeroXJacks
Snipe-IT has incorrect permission for legacy license checkin API Moderate
CVE-2026-55479 was published for snipe/snipe-it (Composer) Aug 28, 2026
Mitchell45 Credited to Mitchell45
Snipe-IT has missing object-level authorization in Kits API Moderate
CVE-2026-55478 was published for snipe/snipe-it (Composer) Aug 28, 2026
Mitchell45 Credited to Mitchell45
Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter Moderate
CVE-2026-55476 was published for snipe/snipe-it (Composer) Aug 28, 2026
iltosec Credited to iltosec and Mitchell45 Mitchell45 Mitchell45
Snipe-IT's import created_by can be overwritten Moderate
CVE-2026-55475 was published for snipe/snipe-it (Composer) Aug 28, 2026
ashrexon Credited to ashrexon
Snipe-IT vulnerable to directory traversal in displaySig High
CVE-2026-55474 was published for snipe/snipe-it (Composer) Aug 28, 2026
Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation Moderate
CVE-2026-55472 was published for snipe/snipe-it (Composer) Aug 28, 2026
Mitchell45 Credited to Mitchell45
Snipe-IT has a path traversal vulnerability via CSV import `image` field Low
CVE-2026-55469 was published for snipe/snipe-it (Composer) Aug 28, 2026
Vasco0x4 Credited to Vasco0x4
Snipe-IT vulnerable to stored XSS via inline-served attachment Moderate
CVE-2026-55466 was published for snipe/snipe-it (Composer) Aug 28, 2026
callmeks Credited to callmeks
Snipe-IT vulnerable to stored XSS via Markdown custom field Moderate
CVE-2026-55464 was published for snipe/snipe-it (Composer) Aug 28, 2026
iltosec Credited to iltosec
Snipe-IT has an authorization bypass on print inventory page Moderate
CVE-2026-55462 was published for snipe/snipe-it (Composer) Aug 28, 2026
mamdouhmahfouz Credited to mamdouhmahfouz
Snipe-IT has an Open Redirect After User Edit Moderate
CVE-2026-55461 was published for snipe/snipe-it (Composer) Aug 28, 2026
mamdouhmahfouz Credited to mamdouhmahfouz
Snipe-IT has an authorization bypass on bulk editing users High
CVE-2026-55460 was published for snipe/snipe-it (Composer) Aug 28, 2026
mamdouhmahfouz Credited to mamdouhmahfouz
ProTip! Advisories are also available from the GraphQL API