GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,904
Maven
5,000+
npm
5,000+
NuGet
967
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,374
Swift
54
Unreviewed advisories
All unreviewed
5,000+
159,143 advisories
Filter by severity
The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for...
Moderate
Unreviewed
CVE-2026-4888
was published
May 28, 2026
Pimcore has a WordExport Authorization Bypass for Unauthorized Document Export
Moderate
CVE-2026-45703
was published
for
pimcore/pimcore
(Composer)
May 27, 2026
AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
Moderate
CVE-2026-45309
was published
for
asyncssh
(pip)
May 27, 2026
ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of...
Moderate
Unreviewed
CVE-2026-9759
was published
May 27, 2026
A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions...
Moderate
Unreviewed
CVE-2026-21785
was published
May 27, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18...
Moderate
Unreviewed
CVE-2026-2601
was published
May 27, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7,...
Moderate
Unreviewed
CVE-2026-1402
was published
May 27, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.10.7, 18...
Moderate
Unreviewed
CVE-2026-5296
was published
May 27, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7,...
Moderate
Unreviewed
CVE-2026-8716
was published
May 27, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7,...
Moderate
Unreviewed
CVE-2026-6713
was published
May 27, 2026
Synfony's HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]
Moderate
CVE-2026-45075
was published
for
symfony/http-kernel
(Composer)
May 27, 2026
Symfony's Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay
Moderate
CVE-2026-45074
was published
for
symfony/security-http
(Composer)
May 27, 2026
Symfony Vulnerable to SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix
Moderate
CVE-2026-45073
was published
for
symfony/cache
(Composer)
May 27, 2026
Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names
Moderate
CVE-2026-45070
was published
for
symfony/mime
(Composer)
May 27, 2026
Symfony's OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims
Moderate
CVE-2026-45069
was published
for
symfony/security-http
(Composer)
May 27, 2026
Symfony has an Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address
Moderate
CVE-2026-45068
was published
for
symfony/mailer
(Composer)
May 27, 2026
Symfony has an HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification
Moderate
CVE-2026-45066
was published
for
symfony/html-sanitizer
(Composer)
May 27, 2026
Symfony's HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing
Moderate
CVE-2026-45064
was published
for
symfony/html-sanitizer
(Composer)
May 27, 2026
CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression
Moderate
CVE-2026-44981
was published
for
github.com/crowdsecurity/crowdsec
(Go)
May 27, 2026
A weakness has been identified in TeamSpeak 3 Server up to 3.13.7. This affects the function...
Moderate
Unreviewed
CVE-2026-4390
was published
May 27, 2026
A vulnerability was detected in TeamSpeak 3 Server up to 3.13.7. This issue affects some unknown...
Moderate
Unreviewed
CVE-2026-4392
was published
May 27, 2026
A security vulnerability has been detected in TeamSpeak 3 Server up to 3.13.7. This vulnerability...
Moderate
Unreviewed
CVE-2026-4391
was published
May 27, 2026
Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2026-49054
was published
May 27, 2026
A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of...
Moderate
Unreviewed
CVE-2026-38931
was published
May 27, 2026
Missing Authorization vulnerability in Bizswoop Account Manager for WooCommerce allows Exploiting...
Moderate
Unreviewed
CVE-2022-41656
was published
May 27, 2026
ProTip!
Advisories are also available from the
GraphQL API