GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,904
Maven
5,000+
npm
5,000+
NuGet
967
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,374
Swift
54
Unreviewed advisories
All unreviewed
5,000+
31,043 advisories
Filter by severity
Kirby CMS has pre-authentication path traversal and PHP file inclusion during user lookup
High
CVE-2026-44177
was published
for
getkirby/cms
(Composer)
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Moderate
CVE-2026-44176
was published
for
getkirby/cms
(Composer)
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
CVE-2026-44175
was published
for
getkirby/cms
(Composer)
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
CVE-2026-44174
was published
for
getkirby/cms
(Composer)
May 26, 2026
FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass
High
CVE-2026-43947
was published
for
fuxa-server
(npm)
May 26, 2026
FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue
High
CVE-2026-43946
was published
for
fuxa-server
(npm)
May 26, 2026
FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection
High
CVE-2026-43945
was published
for
@frangoteam/fuxa
(npm)
May 26, 2026
Yamcs Vulnerable to LDAP Injection in LdapAuthModule
Moderate
CVE-2026-42568
was published
for
org.yamcs:yamcs-core
(Maven)
May 26, 2026
Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
High
CVE-2026-42462
was published
for
@fedify/fedify
(npm)
May 26, 2026
yeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation
High
CVE-2026-42089
was published
for
yeoman-environment
(npm)
May 26, 2026
netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failures
Moderate
CVE-2026-41207
was published
for
io.netty.incubator:netty-incubator-codec-ohttp
(Maven)
May 26, 2026
XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests
High
CVE-2026-48048
was published
for
org.xwiki.platform:xwiki-platform-livetable-ui
(Maven)
May 26, 2026
XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) admin
Moderate
CVE-2026-48047
was published
for
org.xwiki.platform:xwiki-platform-webjars-api
(Maven)
May 26, 2026
Pterodactyl has a database resource limit bypass via race condition in Client API
Low
CVE-2026-35202
was published
for
pterodactyl/panel
(Composer)
May 26, 2026
CryptPad has a Sanitizer Bypass in Diffmarked.js that Allows Arbitrary HTML Injection and Potential XSS
Moderate
CVE-2026-26028
was published
for
cryptpad
(npm)
May 26, 2026
XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName}
Critical
CVE-2026-33137
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
May 26, 2026
Typebot.io has stored XSS via `javascript`: URI in text bubble links — bot author executes JS on visitors' browsers
Moderate
CVE-2026-39964
was published
for
@typebot.io/js
(npm)
May 26, 2026
Typebot has Stored XSS via Rating Block Custom Icon that Bypasses isUnsafe Sandbox in Builder Preview
High
CVE-2026-28445
was published
for
@typebot.io/js
(npm)
May 26, 2026
XWiki Platform has path traversal via resources parameter in ssx and jsx endpoints when using leading slash
Critical
CVE-2026-23734
was published
for
org.xwiki.commons:xwiki-commons-classloader-api
(Maven)
May 26, 2026
Weblate has a Server-Side Request Forgery issue
Moderate
CVE-2025-66407
was published
for
Weblate
(pip)
May 26, 2026
Nezha Monitoring: Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members
Moderate
CVE-2026-47124
was published
for
github.com/nezhahq/nezha
(Go)
May 23, 2026
Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron
Critical
CVE-2026-46716
was published
for
github.com/nezhahq/nezha
(Go)
May 23, 2026
Arcane: Missing admin authorization on global variables endpoint
High
CVE-2026-47125
was published
for
github.com/getarcaneapp/arcane/backend
(Go)
May 23, 2026
instagrapi: Unsafe signup challenge path handling in instagrapi
Moderate
GHSA-ggxf-37hm-9wqf
was published
for
instagrapi
(pip)
May 23, 2026
aiograpi: Unsafe signup challenge path handling
Moderate
CVE-2026-47157
was published
for
aiograpi
(pip)
May 23, 2026
ProTip!
Advisories are also available from the
GraphQL API