GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
47
Go
3,340
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,549
Pub
12
RubyGems
1,012
Rust
1,202
Swift
51
Unreviewed advisories
All unreviewed
5,000+
10,334 advisories
Filter by severity
Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters
High
CVE-2026-33981
was published
for
changedetection.io
(pip)
Mar 27, 2026
In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and...
High
Unreviewed
CVE-2025-15381
was published
Mar 27, 2026
A flaw has been found in OpenBMB XAgent 1.0.0. The impacted element is the function...
Moderate
Unreviewed
CVE-2026-4957
was published
Mar 27, 2026
Dovecot has provided a script to use for attachment to text conversion. This script unsafely...
Moderate
Unreviewed
CVE-2025-59031
was published
Mar 27, 2026
Information disclosure in the file URI processing of File (Field) Paths in Drupal File (Field)...
Moderate
Unreviewed
CVE-2026-1556
was published
Mar 27, 2026
Apollo Router Core: Browser Bug Enables Bypass of XS-Search Prevention via Read-Only Cross-Site Request Forgery
Moderate
GHSA-hff2-gcpx-8f4p
was published
for
apollo-router
(Rust)
Mar 26, 2026
Apollo Server: Browser bug allows for bypass of XS-Search (read-only Cross-Site Request Forgery) prevention
Moderate
GHSA-9q82-xgwf-vj6h
was published
for
@apollo/server
(npm)
Mar 26, 2026
OpenClaw Exposes Credentials Embedded in baseUrl Fields via config.get and channels.status
Moderate
GHSA-ppwq-6v66-5m6j
was published
for
openclaw
(npm)
Mar 26, 2026
Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fields
Moderate
CVE-2026-33886
was published
for
statamic/cms
(Composer)
Mar 26, 2026
Statamic's Markdown preview endpoint exposes sensitive user data
Moderate
CVE-2026-33882
was published
for
statamic/cms
(Composer)
Mar 26, 2026
AVideo: Unauthenticated Access to Scheduler Plugin Endpoints Leaks Scheduled Tasks, Email Content, and User Mappings
Moderate
CVE-2026-33761
was published
for
wwbn/avideo
(Composer)
Mar 26, 2026
Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata
Low
GHSA-44px-qjjc-xrhq
was published
for
craftcms/cms
(Composer)
Mar 26, 2026
HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a...
Low
Unreviewed
CVE-2025-55276
was published
Mar 26, 2026
HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights...
Low
Unreviewed
CVE-2025-55272
was published
Mar 26, 2026
HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue...
Moderate
Unreviewed
CVE-2025-55265
was published
Mar 26, 2026
A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this...
Low
Unreviewed
CVE-2026-4823
was published
Mar 26, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application...
Moderate
Unreviewed
CVE-2025-14915
was published
Mar 25, 2026
Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API
Moderate
CVE-2026-33677
was published
for
code.vikunja.io/api
(Go)
Mar 25, 2026
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and...
Moderate
Unreviewed
CVE-2026-28878
was published
Mar 25, 2026
An authorization issue was addressed with improved state management. This issue is fixed in iOS...
Moderate
Unreviewed
CVE-2026-28877
was published
Mar 25, 2026
This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app...
Moderate
Unreviewed
CVE-2026-28820
was published
Mar 25, 2026
Parse Server exposes auth data via /users/me endpoint
High
CVE-2026-33627
was published
for
parse-server
(npm)
Mar 24, 2026
Craft CMS' anonymous "assets/image-editor" calls return private asset editor metadata to unauthorized users
Low
CVE-2026-33161
was published
for
craftcms/cms
(Composer)
Mar 24, 2026
Information disclosure in the Widget: Cocoa component. This vulnerability affects Firefox < 149...
High
Unreviewed
CVE-2026-4712
was published
Mar 24, 2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6...
Moderate
Unreviewed
CVE-2026-4733
was published
Mar 24, 2026
ProTip!
Advisories are also available from the
GraphQL API