GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
75 advisories
Filter by severity
Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
High
GHSA-pmpg-2mxq-6xwr
was published
for
@budibase/server
(npm)
Jul 24, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug
Moderate
CVE-2026-35596
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme
Moderate
CVE-2026-42597
was published
for
github.com/gotenberg/gotenberg/v7
(Go)
May 7, 2026
Admidio: CSRF on Plugin Install, Uninstall, and Update via Unprotected GET Requests
Moderate
CVE-2026-53760
was published
for
admidio/admidio
(Composer)
Jul 9, 2026
Froxlor: Authenticated customers can read other customers' allowed sender aliases
Moderate
GHSA-mr9h-45p9-fg8h
was published
for
froxlor/froxlor
(Composer)
Jul 2, 2026
Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata
High
CVE-2026-48153
was published
for
@budibase/server
(npm)
Jun 22, 2026
Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
Critical
CVE-2026-48150
was published
for
@budibase/server
(npm)
Jun 12, 2026
Weblate: Stored HTML injection in editor search preview
Moderate
CVE-2026-45106
was published
for
weblate
(pip)
May 15, 2026
pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal
High
CVE-2026-45348
was published
for
pyload-ng
(pip)
May 14, 2026
phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields
High
CVE-2026-46359
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 6, 2026
phpMyFAQ: Path Traversal in Client::deleteClientFolder enables arbitrary directory deletion by non-super-admin admins
Moderate
CVE-2026-45008
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 6, 2026
phpMyFAQ enables unauthenticated 2FA brute-force attack via /admin/check acceptance of arbitrary user-id
Critical
CVE-2026-45010
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 6, 2026
phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query
High
CVE-2026-46366
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 6, 2026
phpMyFAQ has unauthenticated SQL injection via User-Agent header in BuiltinCaptcha
Critical
CVE-2026-46364
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 6, 2026
Lemmy may expose private community data through community, saved, liked, and modlog API views
Moderate
GHSA-95q8-x6r6-672m
was published
for
lemmy_api
(Rust)
May 6, 2026
Private Lemmy instances expose multi-community metadata without authentication
Moderate
GHSA-jmxc-hhwx-gvv3
was published
for
lemmy_api
(Rust)
May 6, 2026
FUXA's scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions
Moderate
CVE-2026-47721
was published
for
fuxa-server
(npm)
Jun 8, 2026
FUXA has SQL Injection in its TDengine DAQ connector via backslash bypass of escapeTdString
Moderate
CVE-2026-47720
was published
for
fuxa-server
(npm)
Jun 8, 2026
FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with response reading
High
CVE-2026-47719
was published
for
fuxa-server
(npm)
Jun 8, 2026
React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
High
CVE-2026-42342
was published
for
@remix-run/server-runtime
(npm)
Jun 3, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Moderate
CVE-2026-44176
was published
for
getkirby/cms
(Composer)
May 26, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root
High
CVE-2026-45576
was published
for
github.com/openziti/zrok
(Go)
May 19, 2026
rok Python ProxyShare can be used as an SSRF proxy through absolute URL paths
Critical
CVE-2026-45568
was published
for
zrok
(pip)
May 19, 2026
Gotenberg has an unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine
High
CVE-2026-42594
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 7, 2026
Gotenberg has arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes
Moderate
CVE-2026-42593
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 7, 2026
ProTip!
Advisories are also available from the
GraphQL API