GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,175
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
170 advisories
Filter by severity
Concrete CMS is vulnerable to unauthenticated page metadata disclosure
Moderate
CVE-2026-8240
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`
Moderate
CVE-2026-46337
was published
for
WWBN/AVideo
(Composer)
May 19, 2026
Sulu: Used API Keys may be available via Admin API
Low
GHSA-9m6v-8fxc-4r44
was published
for
sulu/sulu
(Composer)
May 18, 2026
MantisBT has an Authorization Bypass that Allows Uploading Attachments to Private Issues via REST API
Moderate
CVE-2026-34754
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT Vulnerable to Privilege Escalation from Manager to Administrator
Moderate
CVE-2026-34390
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
Snipe-IT has insecure permissions in file uploads
Critical
CVE-2026-37709
was published
for
snipe/snipe-it
(Composer)
May 8, 2026
phpVMS has an /importer authorization bypass causing full database wipe
Critical
CVE-2026-42569
was published
for
nabeel/phpvms
(Composer)
May 4, 2026
Funadmin has an Improper Access Control Issue
Moderate
CVE-2026-7733
was published
for
funadmin/funadmin
(Composer)
May 4, 2026
FacturaScripts has Insecure Parameter Handling: Unauthorized Modification of Immutable 'nick' Field
Moderate
CVE-2026-32699
was published
for
facturascripts/facturascripts
(Composer)
Apr 28, 2026
goodoneuz/pay-uz: the /payment/api/editable/update endpoint overwrites existing PHP payment hook files
Critical
CVE-2026-31843
was published
for
goodoneuz/pay-uz
(Composer)
Apr 16, 2026
October Rain has a Twig Sandbox Bypass via Collection Methods
Moderate
CVE-2026-22692
was published
for
october/rain
(Composer)
Apr 14, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
High
CVE-2026-34572
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 1, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
High
CVE-2026-34570
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 1, 2026
AVideo: Unauthenticated File Deletion via PHP Operator Precedence Bug in CLI Guard
Moderate
CVE-2026-34733
was published
for
wwbn/avideo
(Composer)
Apr 1, 2026
Admidio allows Unauthenticated Access to Role-Restricted documents via neutralized .htaccess
High
CVE-2026-34381
was published
for
admidio/admidio
(Composer)
Mar 31, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
High
CVE-2026-32299
was published
for
opensource-workshop/connect-cms
(Composer)
Mar 23, 2026
AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection
Critical
CVE-2026-33478
was published
for
wwbn/avideo
(Composer)
Mar 20, 2026
Winter vulnerable to privilege escalation by authenticated backend users
Critical
CVE-2026-27591
was published
for
winter/wn-backend-module
(Composer)
Mar 12, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change
High
GHSA-hr7j-63v7-vj7g
was published
for
github.com/pterodactyl/wings
(Composer)
Feb 17, 2026
phpMyFAQ: Attachment download allowed without dlattachment right (broken access control)
Moderate
CVE-2026-24420
was published
for
phpmyfaq/phpmyfaq
(Composer)
Jan 23, 2026
Pimcore Web2Print Tools Bundle "Favourite Output Channel Configuration" Missing Function Level Authorization
Moderate
CVE-2026-23496
was published
for
pimcore/web2print-tools-bundle
(Composer)
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
Moderate
CVE-2026-23495
was published
for
pimcore/admin-ui-classic-bundle
(Composer)
Jan 15, 2026
Pimcore is Vulnerable to Broken Access Control: Missing Function Level Authorization on "Static Routes" Listing
Moderate
CVE-2026-23494
was published
for
pimcore/pimcore
(Composer)
Jan 15, 2026
Bagisto has IDOR in Customer Order Reorder Functionality
High
CVE-2026-21447
was published
for
bagisto/bagisto
(Composer)
Jan 2, 2026
Neuron MySQLWriteTool allows arbitrary/destructive SQL when exposed to untrusted prompts (agent “footgun”)
Critical
CVE-2025-67510
was published
for
neuron-core/neuron-ai
(Composer)
Dec 9, 2025
ProTip!
Advisories are also available from the
GraphQL API