GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,175
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
3,377 advisories
Filter by severity
TYPO3 sf_register extension allows unauthorized assignment of frontend user groups
Moderate
CVE-2026-46721
was published
for
evoweb/sf-register
(Composer)
May 19, 2026
TYPO3 ke_search path traversal due to lack of normalization on config directory from file indexer
Moderate
CVE-2026-46724
was published
for
tpwd/ke_search
(Composer)
May 19, 2026
TYPO3 ke_search XML External Entity Injection
Moderate
CVE-2026-46722
was published
for
tpwd/ke_search
(Composer)
May 19, 2026
TYPO3 ke_search path traversal from arbitrary table configuration input
Moderate
CVE-2026-46723
was published
for
tpwd/ke_search
(Composer)
May 19, 2026
Statamic Vulnerable to CSV formula injection in form submission exports
Moderate
CVE-2026-54243
was published
for
statamic/cms
(Composer)
Jun 26, 2026
Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)
Moderate
CVE-2026-54242
was published
for
statamic/cms
(Composer)
Jun 26, 2026
Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources
Moderate
CVE-2026-49288
was published
for
statamic/cms
(Composer)
Jun 26, 2026
PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option
Moderate
CVE-2026-49359
was published
for
pontedilana/php-weasyprint
(Composer)
Jun 26, 2026
WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs
Moderate
GHSA-q683-8468-r6h6
was published
for
web-auth/webauthn-symfony-bundle
(Composer)
Jun 26, 2026
CakePHP: View::element() is missing a path containment check
Moderate
CVE-2026-48820
was published
for
cakephp/cakephp
(Composer)
Jun 26, 2026
Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system
Moderate
GHSA-j7f5-gfqm-pcx3
was published
for
pterodactyl/panel
(Composer)
Jun 26, 2026
Concrete CMS is vulnerable to IDOR in surveys
Moderate
CVE-2026-8337
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is Vulnerable to Reflected XSS in Legacy Pagination
Moderate
CVE-2026-8245
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS has a session-hardening bypass and allows password change without reauthorization
Moderate
CVE-2026-8327
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to unauthenticated page metadata disclosure
Moderate
CVE-2026-8240
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to IDOR
Moderate
CVE-2026-8239
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to IDOR
Moderate
CVE-2026-8238
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to IDOR
Moderate
CVE-2026-8237
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to IDOR combined with a missing authentication gate
Moderate
CVE-2026-8236
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to authorization bypass in the Calendar Event Frontend Dialog
Moderate
CVE-2026-8204
was published
for
concrete5/concrete5
(Composer)
May 21, 2026
Concrete CMS is vulnerable to authorization bypass in the Calendar Block
Moderate
CVE-2026-8205
was published
for
concrete5/concrete5
(Composer)
May 21, 2026
Concrete CMS is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block
Moderate
CVE-2026-7881
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS has an unauthorized file access issue
Moderate
CVE-2026-7879
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Snipe-IT Vulnerable to Privilege Escalation via Missing admin Permission Check in User Creation
Moderate
CVE-2026-55483
was published
for
snipe/snipe-it
(Composer)
Jun 23, 2026
Snipe-IT has Multi-Tenancy Bypass via Bulk Asset Update
Moderate
CVE-2026-55482
was published
for
snipe/snipe-it
(Composer)
Jun 23, 2026
ProTip!
Advisories are also available from the
GraphQL API