GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
6,441 advisories
Filter by severity
TYPO3 CMS - Broken Access Control in Backend and Install Tool
High
CVE-2026-19418
was published
for
typo3/cms-backend
(Composer)
Sep 1, 2026
Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used
Moderate
CVE-2026-84306
was published
for
filament/filament
(Composer)
Sep 1, 2026
Filament: Password validity disclosure for accounts denied panel access on login page
Low
CVE-2026-84307
was published
for
filament/filament
(Composer)
Sep 1, 2026
Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled
High
CVE-2026-77567
was published
for
filament/filament
(Composer)
Sep 1, 2026
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension
High
GHSA-8rr7-cvq3-gmfh
was published
for
league/commonmark
(Composer)
Sep 1, 2026
league/commonmark: Denial of service in the SmartPunct and Attributes extensions
High
GHSA-jjv6-8j6v-6j52
was published
for
league/commonmark
(Composer)
Sep 1, 2026
league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed
High
GHSA-f8fg-pg57-v4j8
was published
for
league/commonmark
(Composer)
Sep 1, 2026
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters
High
GHSA-j8pm-gj4c-rq4x
was published
for
league/commonmark
(Composer)
Sep 1, 2026
Smarty: SSRF via redirect bypass of trusted_uri using {fetch}
Moderate
CVE-2026-62993
was published
for
smarty/smarty
(Composer)
Sep 1, 2026
Kirby: System path exposure from error messages in the REST API
Moderate
CVE-2026-69127
was published
for
getkirby/cms
(Composer)
Sep 1, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
CVE-2026-71415
was published
for
getkirby/cms
(Composer)
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
CVE-2026-75594
was published
for
getkirby/cms
(Composer)
Aug 31, 2026
elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback
High
CVE-2026-81889
was published
for
studio-42/elfinder
(Composer)
Aug 31, 2026
TYPO3 CMS - Unrestricted File Upload in Form Framework
Moderate
CVE-2026-15305
was published
for
typo3/cms-form
(Composer)
Aug 31, 2026
Snipe-IT has an Improper Privilege Management issue
High
CVE-2026-55843
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
silverstripe/versioned has XSS in archive admin restore
Moderate
CVE-2026-55779
was published
for
silverstripe/versioned
(Composer)
Aug 28, 2026
PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI
Low
CVE-2026-55891
was published
for
privatebin/privatebin
(Composer)
Aug 28, 2026
PrivateBin has stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction
Moderate
CVE-2026-55696
was published
for
privatebin/privatebin
(Composer)
Aug 28, 2026
Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name
Critical
CVE-2026-55634
was published
for
pimcore/pimcore
(Composer)
Aug 28, 2026
Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column (PHP Object Injection, CWE-502)
Critical
CVE-2026-55220
was published
for
pimcore/pimcore
(Composer)
Aug 28, 2026
Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation
High
CVE-2026-55212
was published
for
pimcore/studio-backend-bundle
(Composer)
Aug 28, 2026
Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
High
CVE-2026-55208
was published
for
pimcore/studio-backend-bundle
(Composer)
Aug 28, 2026
Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
High
CVE-2026-55207
was published
for
pimcore/studio-backend-bundle
(Composer)
Aug 28, 2026
phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers
High
CVE-2026-55584
was published
for
phpsysinfo/phpsysinfo
(Composer)
Aug 28, 2026
Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update
High
CVE-2026-55516
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API