GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
12,530 advisories
Filter by severity
Kirby: File upload permissions are not checked during processing of chunk data
High
CVE-2026-71415
was published
for
getkirby/cms
(Composer)
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
CVE-2026-75594
was published
for
getkirby/cms
(Composer)
Aug 31, 2026
Socket.IO: Engine.IO WebTransport SID DoS
High
CVE-2026-59724
was published
for
engine.io
(npm)
Aug 31, 2026
elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback
High
CVE-2026-81889
was published
for
studio-42/elfinder
(Composer)
Aug 31, 2026
RestrictedPython guard hooks can be shadowed via positional-only arguments
High
CVE-2026-55830
was published
for
RestrictedPython
(pip)
Aug 28, 2026
Snipe-IT has an Improper Privilege Management issue
High
CVE-2026-55843
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
MapFish Print has XXE that allows reading arbitrary files of certain types
High
CVE-2026-55848
was published
for
org.mapfish.print:print-lib
(Maven)
Aug 28, 2026
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI
High
CVE-2026-55784
was published
for
github.com/free5gc/ausf
(Go)
Aug 28, 2026
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
High
CVE-2026-55874
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 28, 2026
Fortigate syslog message parser can be exploited to modify or delete fields from the original message
High
CVE-2026-55841
was published
for
org.graylog2:graylog2-server
(Maven)
Aug 28, 2026
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply
High
CVE-2026-55764
was published
for
github.com/klever-io/klever-go
(Go)
Aug 28, 2026
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
High
CVE-2026-55761
was published
for
github.com/portainer/portainer
(Go)
Aug 28, 2026
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits
High
CVE-2026-55763
was published
for
github.com/klever-io/klever-go
(Go)
Aug 28, 2026
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server
High
CVE-2026-55484
was published
for
github.com/guno1928/alos-http
(Go)
Aug 28, 2026
Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation
High
CVE-2026-55212
was published
for
pimcore/studio-backend-bundle
(Composer)
Aug 28, 2026
Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
High
CVE-2026-55208
was published
for
pimcore/studio-backend-bundle
(Composer)
Aug 28, 2026
Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
High
CVE-2026-55207
was published
for
pimcore/studio-backend-bundle
(Composer)
Aug 28, 2026
MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`
High
CVE-2026-55215
was published
for
mariadb
(npm)
Aug 28, 2026
Incus has a project restriction bypass in instance copy across projects
High
CVE-2026-55622
was published
for
github.com/lxc/incus/v7/cmd/incusd
(Go)
Aug 28, 2026
Incus has a project restriction bypass for custom volume copy across projects
High
CVE-2026-55621
was published
for
github.com/lxc/incus
(Go)
Aug 28, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
High
CVE-2026-55228
was published
for
Weblate
(pip)
Aug 28, 2026
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
High
CVE-2026-55520
was published
for
Protego
(pip)
Aug 28, 2026
PowSyBl Core has Command Injection in LocalCommandExecutor-s
High
CVE-2026-55673
was published
for
com.powsybl:powsybl-computation-local
(Maven)
Aug 28, 2026
Spinnaker: Improper yaml processing on kustomize bake operations
High
CVE-2026-55175
was published
for
io.spinnaker.rosco:rosco-manifests
(Maven)
Aug 28, 2026
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
High
CVE-2026-55641
was published
for
9router
(npm)
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API