GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,227
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,502
Pub
12
RubyGems
995
Rust
1,187
Swift
51
Unreviewed advisories
All unreviewed
5,000+
15 advisories
Filter by severity
Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
High
CVE-2026-32264
was published
for
craftcms/cms
(Composer)
Mar 16, 2026
Craft CMS vulnerable to behavior injection RCE via EntryTypesController
High
CVE-2026-32263
was published
for
craftcms/cms
(Composer)
Mar 16, 2026
Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware
High
GHSA-cwxj-rr6w-m6w7
was published
for
Scrapy
(pip)
Mar 13, 2026
Craft CMS Vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
High
CVE-2026-25498
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
High
CVE-2025-68455
was published
for
craftcms/cms
(Composer)
Jan 5, 2026
AWS Advanced NodeJS Wrapper: Privilege Escalation in Aurora PostgreSQL instance
High
GHSA-8wj8-cfxr-9374
was published
for
aws-advanced-nodejs-wrapper
(npm)
Nov 13, 2025
AWS Advanced Go Wrapper: Privilege Escalation in Aurora PostgreSQL Instance
High
GHSA-7wq2-32h4-9hc9
was published
for
github.com/aws/aws-advanced-go-wrapper/awssql
(Go)
Nov 13, 2025
Amazon Web Services Advanced JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
High
GHSA-7xw4-g7mm-r4hh
was published
for
software.amazon.jdbc:aws-advanced-jdbc-wrapper
(Maven)
Nov 13, 2025
AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance
High
CVE-2025-12967
was published
for
aws_advanced_python_wrapper
(pip)
Nov 13, 2025
generator-jhipster-entity-audit vulnerable to Unsafe Reflection when having Javers selected as Entity Audit Framework
High
CVE-2025-31119
was published
for
generator-jhipster-entity-audit
(npm)
Apr 4, 2025
Unsafe Reflection in base Component class in yiisoft/yii2
High
CVE-2024-4990
was published
for
yiisoft/yii2
(Composer)
Jun 2, 2024
StimulusReflex arbitrary method call
High
CVE-2024-28121
was published
for
stimulus_reflex
(RubyGems)
Mar 12, 2024
avo possible unsafe reflection / partial DoS vulnerability
High
CVE-2023-34102
was published
for
avo
(RubyGems)
Jun 6, 2023
Use of Externally-Controlled Input to Select Classes or Code in Infinispan
High
CVE-2019-10174
was published
for
org.infinispan:infinispan-core
(Maven)
May 24, 2022
Privilege Escalation in Hibernate Validator
High
CVE-2017-7536
was published
for
org.hibernate:hibernate-validator
(Maven)
Jun 15, 2020
ProTip!
Advisories are also available from the
GraphQL API