GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
41
Go
3,080
Maven
5,000+
npm
4,980
NuGet
825
pip
4,417
Pub
12
RubyGems
988
Rust
1,162
Swift
50
Unreviewed advisories
All unreviewed
5,000+
5,283 advisories
Filter by severity
AVideo: Unauthenticated PHP session store exposed to host network via published memcached port
High
CVE-2026-29093
was published
for
wwbn/avideo
(Composer)
Mar 5, 2026
Craft CMS has unauthenticated activation email trigger with potential user enumeration
High
CVE-2026-29069
was published
for
craftcms/cms
(Composer)
Mar 4, 2026
Kimai's API invoice endpoint missing customer-level access control (IDOR)
Moderate
CVE-2026-28685
was published
for
kimai/kimai
(Composer)
Mar 4, 2026
Concrete CMS has a stored Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2026-3242
was published
for
concrete5/concrete5
(Composer)
Mar 4, 2026
Concrete CMS vulnerable to Cross-Site Request Forgery (CSRF)
Low
CVE-2026-2994
was published
for
concrete5/concrete5
(Composer)
Mar 4, 2026
Concrete CMS has a stored Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2026-3240
was published
for
concrete5/concrete5
(Composer)
Mar 4, 2026
Concrete CMS has a stored Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2026-3244
was published
for
concrete5/concrete5
(Composer)
Mar 4, 2026
Concrete CMS has a stored Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2026-3241
was published
for
concrete5/concrete5
(Composer)
Mar 4, 2026
Concrete CMS vulnerable to Remote Code Execution by stored PHP object injection
High
CVE-2026-3452
was published
for
concrete5/concrete5
(Composer)
Mar 4, 2026
Craft CMS has potential authenticated Remote Code Execution via Twig SSTI
Moderate
CVE-2026-28784
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS has Permission Bypass and IDOR in Duplicate Entry Action
Moderate
CVE-2026-28782
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS has Twig Function Blocklist Bypass
Moderate
CVE-2026-28783
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS: Entries Authorship Spoofing via Mass Assignment
Moderate
CVE-2026-28781
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS Vulnerable to Authenticated RCE via "craft.app.fs.write()" in Twig Templates
Critical
CVE-2026-28697
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options
Low
GHSA-4mgv-366x-qxvx
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS has IDOR via GraphQL @parseRefs
High
CVE-2026-28696
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS Vulnerable to Authenticated RCE via Twig SSTI - create() function + Symfony Process gadget
Moderate
CVE-2026-28695
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
WWBN AVideo is vulnerable to unauthenticated OS Command Injection via base64Url in objects/getImage.php
Critical
CVE-2026-29058
was published
for
wwbn/avideo
(Composer)
Mar 3, 2026
OpenSTAManager affected by unauthenticated privilege escalation via modules/utenti/actions.php
Critical
CVE-2026-27012
was published
for
devcode-it/openstamanager
(Composer)
Mar 3, 2026
Froxlor has Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection
Critical
CVE-2026-26279
was published
for
froxlor/froxlor
(Composer)
Mar 3, 2026
OpenSTAManager Affected by XSS in modifica_iva.php via righe parameter
Moderate
CVE-2026-24415
was published
for
devcode-it/openstamanager
(Composer)
Mar 3, 2026
Idno Vulnerable to Remote Code Execution via Chained Import File Write and Template Path Traversal
High
CVE-2026-28507
was published
for
idno/known
(Composer)
Mar 2, 2026
Idno Vulnerable to Unauthenticated SSRF via URL Unfurl Endpoint
Critical
CVE-2026-28508
was published
for
idno/known
(Composer)
Mar 2, 2026
AVideo has Authenticated Remote Code Execution via Unsafe Plugin ZIP Extraction
Critical
CVE-2026-28502
was published
for
wwbn/avideo
(Composer)
Mar 2, 2026
AVideo has Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php
Critical
CVE-2026-28501
was published
for
wwbn/avideo
(Composer)
Mar 2, 2026
ProTip!
Advisories are also available from the
GraphQL API