GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,792 advisories
Filter by severity
Grav: Unauthenticated denial of service via unbounded image derivative dimensions
High
CVE-2026-53653
was published
for
getgrav/grav
(Composer)
Aug 14, 2026
Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name
High
CVE-2026-55072
was published
for
pimcore/pimcore
(Composer)
Aug 13, 2026
Winter: Authenticated backend users can bypass Users controller permission checks
High
CVE-2026-35445
was published
for
winter/wn-backend-module
(Composer)
Aug 12, 2026
Winter: Stored XSS through Editor Settings custom styles
High
CVE-2026-32258
was published
for
winter/wn-backend-module
(Composer)
Aug 12, 2026
Winter: Stored XSS through Brand Settings custom styles
High
CVE-2026-32257
was published
for
winter/wn-backend-module
(Composer)
Aug 12, 2026
CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames
High
CVE-2026-63222
was published
for
codeigniter4/framework
(Composer)
Aug 7, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
CVE-2026-67434
was published
for
squizlabs/php_codesniffer
(Composer)
Aug 6, 2026
Craft CMS: Arbitrary user password reset leading to administrator account takeover
High
GHSA-p8x7-9vfw-p7vc
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS: Authenticated RCE through Twig sandbox escape
High
GHSA-f5wm-88jv-g5hx
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
High
GHSA-265m-7826-wjqm
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
league/commonmark: Denial of service via colliding heading slugs
High
GHSA-mh25-x5hq-wrqp
was published
for
league/commonmark
(Composer)
Aug 6, 2026
league/commonmark: Denial of service via duplicate footnote definitions
High
GHSA-jfm3-95jq-q3rf
was published
for
league/commonmark
(Composer)
Aug 6, 2026
league/commonmark: Denial of service via adjacent inline attribute blocks
High
GHSA-g2gp-3wwq-f4ph
was published
for
league/commonmark
(Composer)
Aug 6, 2026
league/commonmark: Quadratic-time denial of service when parsing crafted Markdown
High
CVE-2026-71488
was published
for
league/commonmark
(Composer)
Aug 6, 2026
Statamic: Account takeover via OAuth email matching without email-verification check
High
CVE-2026-64665
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Guzzle: Noncanonical host can bypass host-based checks
High
CVE-2026-69246
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers
High
GHSA-mqq9-gxg5-m58g
was published
for
guzzlehttp/guzzle
(Composer)
Aug 1, 2026
•
withdrawn
Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved
High
GHSA-mjrx-74jh-7xgw
was published
for
guzzlehttp/guzzle
(Composer)
Aug 1, 2026
•
withdrawn
Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers
High
CVE-2026-53599
was published
for
redaxo/source
(Composer)
Jul 31, 2026
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook
High
CVE-2026-68500
was published
for
sylius/mollie-plugin
(Composer)
Jul 31, 2026
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
High
CVE-2026-55651
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
High
CVE-2026-54593
was published
for
github.com/pterodactyl/wings
(Composer)
Jul 28, 2026
Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
High
CVE-2026-61609
was published
for
pterodactyl/panel
(Composer)
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
High
CVE-2026-45293
was published
for
wp-coding-standards/wpcs
(Composer)
Jul 28, 2026
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
High
GHSA-cmwh-g2h8-c222
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API