GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
201 advisories
Filter by severity
Sulu: Fix authorization bypass when creating preview links
Moderate
CVE-2026-82394
was published
for
sulu/sulu
(Composer)
Sep 2, 2026
Sulu: Media move/update authorization bypass (IDOR)
Moderate
CVE-2026-82395
was published
for
sulu/sulu
(Composer)
Sep 2, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
High
CVE-2026-81892
was published
for
easycorp/easyadmin-bundle
(Composer)
Sep 2, 2026
Snipe-IT has incorrect permission for legacy license checkin API
Moderate
CVE-2026-55479
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Snipe-IT's import created_by can be overwritten
Moderate
CVE-2026-55475
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
Moderate
CVE-2026-55472
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Snipe-IT has an authorization bypass on print inventory page
Moderate
CVE-2026-55462
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Snipe-IT has an authorization bypass on bulk editing users
High
CVE-2026-55460
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
phpMyFAQ public FAQ APIs expose inactive FAQ content
Moderate
GHSA-mf8r-wm2w-f8c5
was published
for
phpmyfaq/phpmyfaq
(Composer)
Aug 25, 2026
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate
High
GHSA-fm29-4mq3-phg6
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)
High
CVE-2026-54180
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode
High
CVE-2026-55643
was published
for
snipe/snipe-it
(Composer)
Aug 19, 2026
Duplicate Advisory: Craft CMS: Authorization bypass: view-only Categories user can modify category structure via structures/move-element
Critical
GHSA-4hc4-qjfx-wjf3
was published
for
craftcms/cms
(Composer)
Aug 11, 2026
•
withdrawn
Craft CMS: Authorization bypass: view-only Categories user can modify category structure via structures/move-element
Moderate
CVE-2026-72785
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the target
Moderate
CVE-2026-52819
was published
for
kimai/kimai
(Composer)
Jul 13, 2026
Sylius: Channel-based payment method restriction bypass on shop account orders API endpoint
Moderate
CVE-2026-53638
was published
for
sylius/sylius
(Composer)
Jul 9, 2026
Mautic has an Authorization Bypass in API v2 Endpoints
High
CVE-2026-9808
was published
for
mautic/core
(Composer)
Jul 2, 2026
Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
High
CVE-2026-49981
was published
for
twig/twig
(Composer)
Jul 1, 2026
Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
Moderate
CVE-2026-48808
was published
for
twig/twig
(Composer)
Jun 30, 2026
Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
Moderate
CVE-2026-48807
was published
for
twig/twig
(Composer)
Jun 30, 2026
Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys
Moderate
CVE-2026-48806
was published
for
twig/twig
(Composer)
Jun 30, 2026
Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors
Low
CVE-2026-54244
was published
for
statamic/cms
(Composer)
Jun 26, 2026
Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources
Moderate
CVE-2026-49288
was published
for
statamic/cms
(Composer)
Jun 26, 2026
Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
High
CVE-2026-48507
was published
for
snipe/snipe-it
(Composer)
Jun 23, 2026
Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
Moderate
CVE-2026-48493
was published
for
snipe/snipe-it
(Composer)
Jun 23, 2026
ProTip!
Advisories are also available from the
GraphQL API