GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,821
Maven
5,000+
npm
5,000+
NuGet
939
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
3,233 advisories
Filter by severity
AVideo CVE-2026-43884 incomplete fix - six (or more) `isSSRFSafeURL()` call sites still discard the `$resolvedIP` out-param at master HEAD post-`603e7bf`
Moderate
CVE-2026-45619
was published
for
WWBN/AVideo
(Composer)
May 15, 2026
AVideo: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FA
Moderate
CVE-2026-45610
was published
for
WWBN/AVideo
(Composer)
May 15, 2026
AVideo: stored XSS via unescaped stream key in modeYoutubeLive.php class attribute
Moderate
CVE-2026-45580
was published
for
WWBN/AVideo
(Composer)
May 15, 2026
SimpleSAMLphp casserver: Open Redirect in logout
Moderate
CVE-2025-65954
was published
for
simplesamlphp/simplesamlphp-module-casserver
(Composer)
May 15, 2026
MantisBT: Authorization Bypass in Bugnote Editing via Issue Update API
Moderate
CVE-2026-42070
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT is Vulnerable to Reflected XSS in Rendering Dynamic Custom Textarea Field
Moderate
CVE-2026-41897
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update Page
Moderate
CVE-2026-40598
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT is Vulnerable to Stored XSS in Custom Field Textarea Values
Moderate
CVE-2026-39960
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT: Bugnote Revision Page Leaks Private Issue Metadata After Issue Access Is Revoked
Moderate
CVE-2026-34970
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT has an Authorization Bypass that Allows Uploading Attachments to Private Issues via REST API
Moderate
CVE-2026-34754
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT has an authorization bypass that allows reading attachments after losing access to a private issue
Moderate
CVE-2026-34744
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT has an authorization bypass in private issue monitoring
Moderate
CVE-2026-34579
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT Vulnerable to Privilege Escalation from Manager to Administrator
Moderate
CVE-2026-34390
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT Has Authorization Bypass in Global Profile Creation
Moderate
CVE-2026-33052
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
Snipe-IT has an open redirect vulnerability
Moderate
CVE-2026-44833
was published
for
snipe/snipe-it
(Composer)
May 8, 2026
Snipe-IT has Stored XSS via Component Checkout Notes (v8.4.0)
Moderate
CVE-2026-44831
was published
for
snipe/snipe-it
(Composer)
May 8, 2026
Kimai has an arbitrary file read in its invoice PDF renderer (admin)
Moderate
CVE-2026-44298
was published
for
kimai/kimai
(Composer)
May 8, 2026
Grav: Stored XSS via page title (data[header][title]) in admin panel
Moderate
CVE-2026-44737
was published
for
getgrav/grav
(Composer)
May 8, 2026
FacturaScripts Vulnerable to Authenticated Remote Code Execution (RCE) via GIF Image Upload in Product Images
Moderate
CVE-2026-42879
was published
for
facturascripts/facturascripts
(Composer)
May 7, 2026
FacturaScripts Vulnerable to Unauthenticated phpinfo() Disclosure via Installer Endpoint
Moderate
CVE-2026-42878
was published
for
facturascripts/facturascripts
(Composer)
May 7, 2026
FacturaScripts vulnerable to stored XSS via product reference in sales/purchases
Moderate
CVE-2026-42877
was published
for
facturascripts/facturascripts
(Composer)
May 7, 2026
FacturaScripts Vulnerable to Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/Download
Moderate
CVE-2026-27892
was published
for
facturascripts/facturascripts
(Composer)
May 7, 2026
Webkul Krayin CRM is Vulnerable to Cross-Site Scripting in the /admin/activities/create endpoint
Moderate
CVE-2026-36341
was published
for
krayin/laravel-crm
(Composer)
May 7, 2026
Flight has path traversal in `make:controller` CLI that creates arbitrary directories outside project root
Moderate
CVE-2026-42549
was published
for
flightphp/core
(Composer)
May 6, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Moderate
CVE-2026-42458
was published
for
openmage/magento-lts
(Composer)
May 6, 2026
ProTip!
Advisories are also available from the
GraphQL API