GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
43 advisories
Filter by severity
Statamic: Account takeover via OAuth email matching without email-verification check
High
CVE-2026-64665
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
High
GHSA-cmwh-g2h8-c222
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Kimai: Pre-2FA KIMAI_SESSION cookie grants full authenticated REST API access, bypassing TOTP
High
CVE-2026-52827
was published
for
kimai/kimai
(Composer)
Jul 14, 2026
Froxlor's API Authentication bypasses 2FA Authentication
High
CVE-2026-52793
was published
for
froxlor/froxlor
(Composer)
Jun 3, 2026
AVideo's Meet plugin: `uploadRecordedVideo.json.php` derives `users_id` from the uploaded filename and calls passwordless `User->login()`, allowing any caller with the Meet shared secret to obtain a session as arbitrary users including admin
High
GHSA-qxvm-r42f-5p8j
was published
for
WWBN/AVideo
(Composer)
May 15, 2026
Laravel Passport: TokenGuard Authenticates Unrelated User for Client Credentials Tokens
High
CVE-2026-39976
was published
for
laravel/passport
(Composer)
Apr 8, 2026
AVideo has an unauthenticated decrypt oracle leaking any ciphertext
High
CVE-2026-33512
was published
for
wwbn/avideo
(Composer)
Mar 20, 2026
AVideo: Unauthenticated PHP session store exposed to host network via published memcached port
High
CVE-2026-29093
was published
for
wwbn/avideo
(Composer)
Mar 5, 2026
Craft CMS has unauthenticated activation email trigger with potential user enumeration
High
CVE-2026-29069
was published
for
craftcms/cms
(Composer)
Mar 4, 2026
Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypass
High
CVE-2026-27939
was published
for
statamic/cms
(Composer)
Feb 27, 2026
Filament multi-factor authentication (app) recovery codes can be used multiple times
High
CVE-2025-67507
was published
for
filament/filament
(Composer)
Dec 9, 2025
TYPO3 Modules Extension has Improper Authentication vulnerability
High
CVE-2025-12998
was published
for
codingms/modules
(Composer)
Nov 12, 2025
Joomla CMS Multi-Factor Authentication Bypass
High
CVE-2025-25227
was published
for
joomla/joomla-cms
(Composer)
Apr 8, 2025
Socialstream has a Potential Account Takeover Vulnerability in Social Account Linking Due to Missing User Consent After OAuth Callback
High
CVE-2024-56329
was published
for
joelbutcher/socialstream
(Composer)
Dec 20, 2024
Symfony has an Authentication Bypass via RememberMe
High
CVE-2024-51996
was published
for
symfony/security-http
(Composer)
Nov 13, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
CVE-2022-25768
was published
for
mautic/core
(Composer)
Sep 18, 2024
ZendOpenID potential security issue in login mechanism
High
GHSA-3x57-m5p4-rgh4
was published
for
zendframework/zendopenid
(Composer)
Jun 7, 2024
Zendframework potential security issue in login mechanism
High
GHSA-9v78-h226-2rmq
was published
for
zendframework/zendframework1
(Composer)
Jun 7, 2024
TYPO3 Security Misconfiguration for Backend User Accounts
High
GHSA-c5mj-39cf-3pp5
was published
for
typo3/cms
(Composer)
Jun 7, 2024
TYPO3 Security Misconfiguration for Backend User Accounts
High
GHSA-rxc9-f2x6-qh4w
was published
for
typo3/cms-core
(Composer)
May 30, 2024
TYPO3 CMS Authentication Bypass vulnerability
High
GHSA-x4rj-f7m6-42c3
was published
for
typo3/cms-core
(Composer)
May 30, 2024
Thelia authentication bypass vulnerability
High
GHSA-g8pg-33v4-9r96
was published
for
thelia/thelia
(Composer)
May 30, 2024
scheb/two-factor-bundle bypass two-factor authentication with remember-me option
High
GHSA-9phw-7h96-q3rv
was published
for
scheb/two-factor-bundle
(Composer)
May 21, 2024
scheb/two-factor-bundle bypass two-factor authentication with unverified JWT trusted device token
High
GHSA-h6mp-mc7g-mg49
was published
for
scheb/two-factor-bundle
(Composer)
May 21, 2024
Remote Code Execution by uploading a phar file using frontmatter
High
CVE-2024-27923
was published
for
getgrav/grav
(Composer)
Mar 6, 2024
ProTip!
Advisories are also available from the
GraphQL API