GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,511
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,512
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
344 advisories
Filter by severity
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover
High
CVE-2026-45627
was published
for
github.com/getarcaneapp/arcane/backend
(Go)
May 18, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter
Moderate
CVE-2026-45626
was published
for
github.com/getarcaneapp/arcane/backend
(Go)
May 18, 2026
Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs
Critical
CVE-2026-45625
was published
for
github.com/getarcaneapp/arcane/backend
(Go)
May 18, 2026
AVideo: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FA
Moderate
CVE-2026-45610
was published
for
WWBN/AVideo
(Composer)
May 15, 2026
AVideo: stored XSS via unescaped stream key in modeYoutubeLive.php class attribute
Moderate
CVE-2026-45580
was published
for
WWBN/AVideo
(Composer)
May 15, 2026
AVideo: OS command injection in on_publish.php execAsync via unescaped m3u8 URL
High
CVE-2026-45578
was published
for
WWBN/AVideo
(Composer)
May 15, 2026
AVideo's Meet plugin: `uploadRecordedVideo.json.php` derives `users_id` from the uploaded filename and calls passwordless `User->login()`, allowing any caller with the Meet shared secret to obtain a session as arbitrary users including admin
High
GHSA-qxvm-r42f-5p8j
was published
for
WWBN/AVideo
(Composer)
May 15, 2026
goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request
High
GHSA-mxg3-432p-mr72
was published
for
goshs.de/goshs/v2
(Go)
May 15, 2026
FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover
High
CVE-2026-46480
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover
High
CVE-2026-46479
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover
High
CVE-2026-46478
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover
High
CVE-2026-46477
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: CustomTemplate create+update mass-assignment allows cross-workspace template takeover
High
CVE-2026-46476
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover
High
CVE-2026-46475
was published
for
flowise
(npm)
May 14, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
Moderate
CVE-2026-40295
was published
for
devise
(RubyGems)
May 8, 2026
Webauthn has a User Verification Downgrade via Default-Open ClientOverridePolicy
Low
GHSA-h4fw-6r7f-w494
was published
for
web-auth/webauthn-framework
(Composer)
May 7, 2026
Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS
High
CVE-2026-42587
was published
for
io.netty:netty-codec-http
(Maven)
May 7, 2026
kube-router: GoBGP gRPC Admin Port Exposed on Node Primary IP Without Authentication, Allowing Cluster-Wide BGP Route Injection
Moderate
GHSA-v5mh-h5hx-7v92
was published
for
github.com/cloudnativelabs/kube-router
(Go)
May 6, 2026
phpMyFAQ's Missing CONFIGURATION_EDIT Permission Check on 12 Admin API Configuration Tab Endpoints Allows Information Disclosure by Any Authenticated User
Moderate
CVE-2026-45007
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 6, 2026
phpMyFAQ has a SVG Sanitizer Entity Decoding Depth Limit Bypass Leading to Stored XSS
Moderate
CVE-2026-46360
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 6, 2026
phpMyFAQ has Stored XSS in FAQ Question/Answer via Encode-Decode Bypass of removeAttributes() Sanitization
Moderate
CVE-2026-46363
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 6, 2026
phpMyFAQ's Missing Authorization on Tag Deletion Allows Any Authenticated User to Delete Tags
Moderate
GHSA-7cx3-2qx2-3g6w
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 6, 2026
phpMyFAQ has an Authorization Bypass in All Admin Pages Due to Non-Terminating Permission Check
Moderate
CVE-2026-46362
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 6, 2026
Micronaut has unbounded `formattersCache` in `TimeConverterRegistrar` that Allows Memory Exhaustion via `Accept-Language` Header
High
CVE-2026-44241
was published
for
io.micronaut:micronaut-context
(Maven)
May 6, 2026
Micronaut has Unbounded `bundleCache` in `ResourceBundleMessageSource` that Allows Memory Exhaustion via `Accept-Language` Header
Low
CVE-2026-44242
was published
for
io.micronaut:micronaut-inject
(Maven)
May 6, 2026
ProTip!
Advisories are also available from the
GraphQL API