GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
47
Go
3,340
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,549
Pub
12
RubyGems
1,012
Rust
1,202
Swift
51
Unreviewed advisories
All unreviewed
5,000+
11 advisories
Filter by severity
Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata
Low
GHSA-44px-qjjc-xrhq
was published
for
craftcms/cms
(Composer)
Mar 26, 2026
Craft CMS' anonymous "assets/image-editor" calls return private asset editor metadata to unauthorized users
Low
CVE-2026-33161
was published
for
craftcms/cms
(Composer)
Mar 24, 2026
Craft CMS may expose private assets through anonymous "generate transform" calls via transform URL
Low
CVE-2026-33160
was published
for
craftcms/cms
(Composer)
Mar 24, 2026
AzuraCast Vulnerable to Pre-Auth File Deletion & Admin RCE
Low
CVE-2025-67737
was published
for
azuracast/azuracast
(Composer)
Dec 11, 2025
Moodle doesn't properly check role
Low
CVE-2010-1617
was published
for
moodle/moodle
(Composer)
May 13, 2022
Leantime has Missing Authorization Check for Host Parameter
Low
GHSA-3hfj-qcvj-4hx8
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Froxlor vulnerable to business logic errors
Low
CVE-2023-4304
was published
for
froxlor/froxlor
(Composer)
Aug 11, 2023
Silverstripe Framework: Members with no password can be created and bypass custom login forms
Low
CVE-2023-32302
was published
for
silverstripe/framework
(Composer)
Jul 31, 2023
Any Flarum user including unactivated can reply in public discussions whose first post was permanently deleted
Low
CVE-2023-22489
was published
for
flarum/core
(Composer)
Jan 10, 2023
Generation of fake documents via public GET-call
Low
GHSA-jvg4-9rc2-wvcr
was published
for
shopware/platform
(Composer)
Feb 10, 2021
Bypass of fix for CVE-2020-15247, Twig sandbox escape
Low
CVE-2020-26231
was published
for
october/cms
(Composer)
Nov 23, 2020
ProTip!
Advisories are also available from the
GraphQL API