GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
55
GitHub Actions
50
Go
3,732
Maven
5,000+
npm
5,000+
NuGet
935
pip
4,952
Pub
13
RubyGems
1,055
Rust
1,343
Swift
54
Unreviewed advisories
All unreviewed
5,000+
163 advisories
Filter by severity
phpVMS has an /importer authorization bypass causing full database wipe
Critical
CVE-2026-42569
was published
for
nabeel/phpvms
(Composer)
May 4, 2026
FacturaScripts has Insecure Parameter Handling: Unauthorized Modification of Immutable 'nick' Field
Moderate
CVE-2026-32699
was published
for
facturascripts/facturascripts
(Composer)
Apr 28, 2026
goodoneuz/pay-uz: the /payment/api/editable/update endpoint overwrites existing PHP payment hook files
Critical
CVE-2026-31843
was published
for
goodoneuz/pay-uz
(Composer)
Apr 16, 2026
October Rain has a Twig Sandbox Bypass via Collection Methods
Moderate
CVE-2026-22692
was published
for
october/rain
(Composer)
Apr 14, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
High
CVE-2026-34572
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 1, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
High
CVE-2026-34570
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 1, 2026
AVideo: Unauthenticated File Deletion via PHP Operator Precedence Bug in CLI Guard
Moderate
CVE-2026-34733
was published
for
wwbn/avideo
(Composer)
Apr 1, 2026
Admidio allows Unauthenticated Access to Role-Restricted documents via neutralized .htaccess
High
CVE-2026-34381
was published
for
admidio/admidio
(Composer)
Mar 31, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
High
CVE-2026-32299
was published
for
opensource-workshop/connect-cms
(Composer)
Mar 23, 2026
AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection
Critical
CVE-2026-33478
was published
for
wwbn/avideo
(Composer)
Mar 20, 2026
Winter vulnerable to privilege escalation by authenticated backend users
Critical
CVE-2026-27591
was published
for
winter/wn-backend-module
(Composer)
Mar 12, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change
High
GHSA-hr7j-63v7-vj7g
was published
for
github.com/pterodactyl/wings
(Composer)
Feb 17, 2026
phpMyFAQ: Attachment download allowed without dlattachment right (broken access control)
Moderate
CVE-2026-24420
was published
for
phpmyfaq/phpmyfaq
(Composer)
Jan 23, 2026
Pimcore Web2Print Tools Bundle "Favourite Output Channel Configuration" Missing Function Level Authorization
Moderate
CVE-2026-23496
was published
for
pimcore/web2print-tools-bundle
(Composer)
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
Moderate
CVE-2026-23495
was published
for
pimcore/admin-ui-classic-bundle
(Composer)
Jan 15, 2026
Pimcore is Vulnerable to Broken Access Control: Missing Function Level Authorization on "Static Routes" Listing
Moderate
CVE-2026-23494
was published
for
pimcore/pimcore
(Composer)
Jan 15, 2026
Bagisto has IDOR in Customer Order Reorder Functionality
High
CVE-2026-21447
was published
for
bagisto/bagisto
(Composer)
Jan 2, 2026
Neuron MySQLWriteTool allows arbitrary/destructive SQL when exposed to untrusted prompts (agent “footgun”)
Critical
CVE-2025-67510
was published
for
neuron-core/neuron-ai
(Composer)
Dec 9, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
CVE-2025-13828
was published
for
mautic/core
(Composer)
Dec 2, 2025
phppgadmin contains an incorrect access control vulnerability
Moderate
CVE-2025-60799
was published
for
phppgadmin/phppgadmin
(Composer)
Nov 20, 2025
Moodle course access permissions are not properly checked in course_output_fragment_course_overview
Moderate
CVE-2025-62393
was published
for
moodle/moodle
(Composer)
Oct 23, 2025
phpMyFAQ duplicate email registration allows multiple accounts with the same email
High
CVE-2025-59943
was published
for
thorsten/phpmyfaq
(Composer)
Oct 3, 2025
Contao applies improper access control in the back end voters
Moderate
CVE-2025-57758
was published
for
contao/contao
(Composer)
Aug 28, 2025
UnoPim has Broken Access Control
High
CVE-2025-55741
was published
for
unopim/unopim
(Composer)
Aug 22, 2025
Magento Improper Access Control leads to security feature bypass
Moderate
CVE-2025-27206
was published
for
magento/community-edition
(Composer)
Jun 10, 2025
ProTip!
Advisories are also available from the
GraphQL API