GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
55
GitHub Actions
50
Go
3,732
Maven
5,000+
npm
5,000+
NuGet
935
pip
4,952
Pub
13
RubyGems
1,055
Rust
1,343
Swift
54
Unreviewed advisories
All unreviewed
5,000+
290 advisories
Filter by severity
FacturaScripts Vulnerable to Unauthenticated phpinfo() Disclosure via Installer Endpoint
Moderate
CVE-2026-42878
was published
for
facturascripts/facturascripts
(Composer)
May 7, 2026
FacturaScripts Vulnerable to Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/Download
Moderate
CVE-2026-27892
was published
for
facturascripts/facturascripts
(Composer)
May 7, 2026
AVideo Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization
High
CVE-2026-43885
was published
for
wwbn/avideo
(Composer)
May 5, 2026
Admidio Leaks Hidden Profile Field Values via Blind Search Oracle in Member Assignment
Low
CVE-2026-41659
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
October CMS has Safe Mode Bypass via CSS Preprocessor Compilers
Moderate
CVE-2026-26067
was published
for
october/system
(Composer)
Apr 21, 2026
WWBN AVideo has an Unauthenticated Information Disclosure via git.json.php Exposes Developer Emails and Deployed Version
Moderate
CVE-2026-40908
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
October Rain has Environment Variable Exfiltration via INI Parser Interpolation
Moderate
CVE-2026-25125
was published
for
october/rain
(Composer)
Apr 14, 2026
Craft Commerce has an unauthenticated information disclosure that can leak some customer order data on anonymous payments
Low
CVE-2026-32270
was published
for
craftcms/commerce
(Composer)
Apr 14, 2026
AVideo: Unauthenticated Information Disclosure via Missing Auth on CloneSite client.log.php
Moderate
CVE-2026-35452
was published
for
wwbn/avideo
(Composer)
Apr 4, 2026
AVideo: Unauthenticated Information Disclosure via Disabled CLI Guard in install/test.php
Moderate
CVE-2026-35449
was published
for
wwbn/avideo
(Composer)
Apr 4, 2026
AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
High
GHSA-wprj-9cvc-5w37
was published
for
wwbn/avideo
(Composer)
Mar 29, 2026
Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fields
Moderate
CVE-2026-33886
was published
for
statamic/cms
(Composer)
Mar 26, 2026
Statamic's Markdown preview endpoint exposes sensitive user data
Moderate
CVE-2026-33882
was published
for
statamic/cms
(Composer)
Mar 26, 2026
AVideo: Unauthenticated Access to Scheduler Plugin Endpoints Leaks Scheduled Tasks, Email Content, and User Mappings
Moderate
CVE-2026-33761
was published
for
wwbn/avideo
(Composer)
Mar 26, 2026
Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata
Low
GHSA-44px-qjjc-xrhq
was published
for
craftcms/cms
(Composer)
Mar 26, 2026
Craft CMS' anonymous "assets/image-editor" calls return private asset editor metadata to unauthorized users
Low
CVE-2026-33161
was published
for
craftcms/cms
(Composer)
Mar 24, 2026
Sprig Plugin for Craft CMS potentially discloses sensitive information via Sprig Playground
Moderate
CVE-2026-27131
was published
for
putyourlightson/craft-sprig
(Composer)
Mar 23, 2026
AVideo has an Unauthenticated Password Hash Oracle via encryptPass.json.php
Moderate
CVE-2026-33041
was published
for
wwbn/avideo
(Composer)
Mar 17, 2026
Broken Access Control in extension "Redirect Tab" (redirect_tab)
Low
CVE-2026-4202
was published
for
ayacoo/redirect-tab
(Composer)
Mar 17, 2026
Google Cloud Storage for Craft CMS has an Information Disclosure Vulnerability
Low
CVE-2026-32266
was published
for
craftcms/google-cloud
(Composer)
Mar 16, 2026
Amazon S3 for Craft CMS has an Information Disclosure vulnerability
Moderate
CVE-2026-32265
was published
for
craftcms/aws-s3
(Composer)
Mar 16, 2026
funadmin exposes sensitive information via getMember function
Moderate
CVE-2026-2894
was published
for
funadmin/funadmin
(Composer)
Feb 22, 2026
Known affected by Account Takeover via Password Reset Token Leakage
Critical
CVE-2026-26273
was published
for
idno/known
(Composer)
Feb 13, 2026
Magento's X-Original-Url header can expose admin url
Moderate
CVE-2026-25523
was published
for
openmage/magento-lts
(Composer)
Feb 2, 2026
phpMyFAQ: Public API endpoints expose emails and invisible questions
Moderate
CVE-2026-24422
was published
for
phpmyfaq/phpmyfaq
(Composer)
Jan 23, 2026
ProTip!
Advisories are also available from the
GraphQL API