GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
50
GitHub Actions
50
Go
3,673
Maven
5,000+
npm
5,000+
NuGet
932
pip
4,891
Pub
13
RubyGems
1,051
Rust
1,315
Swift
53
Unreviewed advisories
All unreviewed
5,000+
1,579 advisories
Filter by severity
AVideo Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization
High
CVE-2026-43885
was published
for
wwbn/avideo
(Composer)
May 5, 2026
AVideo has SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL()
High
CVE-2026-43884
was published
for
wwbn/avideo
(Composer)
May 5, 2026
Grav is Vulnerable to Stored XSS via Tag Injection
High
CVE-2026-42611
was published
for
getgrav/grav
(Composer)
May 5, 2026
Grav has Unauthenticated Path Traversal & Arbitrary File Write in its FormFlash component
High
CVE-2026-42608
was published
for
getgrav/grav
(Composer)
May 5, 2026
Grav Vulnerable to Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic
High
CVE-2026-42609
was published
for
getgrav/grav
(Composer)
May 5, 2026
Grav has Insecure Deserialization in File Cache
High
GHSA-gwfr-jfjf-92vv
was published
for
getgrav/grav
(Composer)
May 5, 2026
Grav Vulnerable to Publisher-Level Stored XSS via Unquoted Event Attributes
High
CVE-2026-42612
was published
for
getgrav/grav
(Composer)
May 5, 2026
Grav API Privilege Escalation to Super Admin
High
CVE-2026-42843
was published
for
getgrav/grav-plugin-api
(Composer)
May 5, 2026
phpseclib has a CVE-2024-27355 mitigation bypass — OID amplification DoS in ASN1::decodeOID()
High
CVE-2026-44167
was published
for
phpseclib/phpseclib
(Composer)
May 5, 2026
AVideo has an Incomplete Fix for YPTSocket autoEvalCodeOnHTML Strip: Unauthenticated Cross-User JavaScript Execution via `$msg['json']` Relay Bypass
High
CVE-2026-43874
was published
for
wwbn/avideo
(Composer)
May 5, 2026
AVideo: Unauthenticated Disclosure of CloneSite `myKey` via Error Echo in `cloneClient.json.php` Enables Cross-Site DB Dump of the Configured Clone Server
High
CVE-2026-43873
was published
for
wwbn/avideo
(Composer)
May 5, 2026
webonyx/graphql-php has unbounded recursion in parser that causes stack overflow on crafted nested input
High
GHSA-r7cg-qjjm-xhqq
was published
for
webonyx/graphql-php
(Composer)
May 5, 2026
webonyx/graphql-php has quadratic validation cost in OverlappingFieldsCanBeMerged via inline fragments
High
GHSA-fc86-6rv6-2jpm
was published
for
webonyx/graphql-php
(Composer)
May 4, 2026
livewire-markdown-editor has arbitrary file upload that allows stored XSS via attachment handler
High
GHSA-gxxh-8vcj-w2mh
was published
for
mckenziearts/livewire-markdown-editor
(Composer)
May 4, 2026
AzuraCast Vulnerable to Liquidsoap Code Injection via Incomplete cleanUpString-to-toRawString Migration in Remote Relay Password Field
High
GHSA-q4ph-8x8g-95f8
was published
for
azuracast/azuracast
(Composer)
May 4, 2026
AzuraCast has Password Reset Poisoning via Untrusted X-Forwarded-Host Header that Leads to Account Takeover and 2FA Bypass
High
CVE-2026-42606
was published
for
azuracast/azuracast
(Composer)
May 4, 2026
AzuraCast has Path Traversal in `currentDirectory` Parameter that Enables Remote Code Execution via Media Upload
High
CVE-2026-42605
was published
for
azuracast/azuracast
(Composer)
May 4, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
CVE-2026-42069
was published
for
getkirby/cms
(Composer)
May 4, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
CVE-2026-42137
was published
for
getkirby/cms
(Composer)
Apr 30, 2026
Admidio Sends SAML Response to Unvalidated Assertion Consumer Service URL from AuthnRequest
High
CVE-2026-41670
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio Ignores SAML Signature Validation Result, Processes Forged AuthnRequests and LogoutRequests
High
CVE-2026-41669
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio has Inverted 2FA Reset Authorization Check that Lets Group Leaders Strip Admin TOTP
High
CVE-2026-41660
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
ipl/web is vulnerable to reflected XSS by malformed search requests
High
CVE-2026-42224
was published
for
ipl/web
(Composer)
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
CVE-2026-41587
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 29, 2026
PhpSpreadsheet has CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions
High
CVE-2026-40902
was published
for
phpoffice/phpspreadsheet
(Composer)
Apr 29, 2026
ProTip!
Advisories are also available from the
GraphQL API