GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,784 advisories
Filter by severity
CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames
High
CVE-2026-63222
was published
for
codeigniter4/framework
(Composer)
Aug 7, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
CVE-2026-67434
was published
for
squizlabs/php_codesniffer
(Composer)
Aug 6, 2026
Craft CMS: Arbitrary user password reset leading to administrator account takeover
High
GHSA-p8x7-9vfw-p7vc
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS: Authenticated RCE through Twig sandbox escape
High
GHSA-f5wm-88jv-g5hx
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
High
GHSA-265m-7826-wjqm
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
league/commonmark: Denial of service via colliding heading slugs
High
GHSA-mh25-x5hq-wrqp
was published
for
league/commonmark
(Composer)
Aug 6, 2026
league/commonmark: Denial of service via duplicate footnote definitions
High
GHSA-jfm3-95jq-q3rf
was published
for
league/commonmark
(Composer)
Aug 6, 2026
league/commonmark: Denial of service via adjacent inline attribute blocks
High
GHSA-g2gp-3wwq-f4ph
was published
for
league/commonmark
(Composer)
Aug 6, 2026
league/commonmark: Quadratic-time denial of service when parsing crafted Markdown
High
CVE-2026-71488
was published
for
league/commonmark
(Composer)
Aug 6, 2026
Statamic: Account takeover via OAuth email matching without email-verification check
High
CVE-2026-64665
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Guzzle: Noncanonical host can bypass host-based checks
High
CVE-2026-69246
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers
High
GHSA-mqq9-gxg5-m58g
was published
for
guzzlehttp/guzzle
(Composer)
Aug 1, 2026
•
withdrawn
Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved
High
GHSA-mjrx-74jh-7xgw
was published
for
guzzlehttp/guzzle
(Composer)
Aug 1, 2026
•
withdrawn
Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers
High
CVE-2026-53599
was published
for
redaxo/source
(Composer)
Jul 31, 2026
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook
High
CVE-2026-68500
was published
for
sylius/mollie-plugin
(Composer)
Jul 31, 2026
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
High
CVE-2026-55651
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
High
CVE-2026-54593
was published
for
github.com/pterodactyl/wings
(Composer)
Jul 28, 2026
Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
High
CVE-2026-61609
was published
for
pterodactyl/panel
(Composer)
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
High
CVE-2026-45293
was published
for
wp-coding-standards/wpcs
(Composer)
Jul 28, 2026
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
High
GHSA-cmwh-g2h8-c222
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
High
GHSA-rm67-g9ch-vxff
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
High
GHSA-h4hf-v6w5-897x
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes
High
GHSA-g3hq-hphg-8fhh
was published
for
pheditor/pheditor
(Composer)
Jul 24, 2026
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
High
CVE-2026-59933
was published
for
phpoffice/phpspreadsheet
(Composer)
Jul 23, 2026
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
High
CVE-2026-59932
was published
for
phpoffice/phpspreadsheet
(Composer)
Jul 23, 2026
ProTip!
Advisories are also available from the
GraphQL API