GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
15 advisories
Filter by severity
FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with response reading
High
CVE-2026-47719
was published
for
fuxa-server
(npm)
Jun 8, 2026
React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
High
CVE-2026-42342
was published
for
@remix-run/server-runtime
(npm)
Jun 3, 2026
zrok copy writes attacker-controlled WebDAV paths outside the destination root
High
CVE-2026-45576
was published
for
github.com/openziti/zrok
(Go)
May 19, 2026
pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal
High
CVE-2026-45348
was published
for
pyload-ng
(pip)
May 14, 2026
ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI
High
GHSA-fpw6-hrg5-q5x5
was published
for
github.com/lin-snow/Ech0
(Go)
May 7, 2026
Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft
High
GHSA-p64j-f4x9-wq66
was published
for
github.com/lin-snow/Ech0
(Go)
May 7, 2026
Gotenberg has an unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine
High
CVE-2026-42594
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 7, 2026
phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query
High
CVE-2026-46366
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 6, 2026
phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields
High
CVE-2026-46359
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 6, 2026
Admidio has Inverted 2FA Reset Authorization Check that Lets Group Leaders Strip Admin TOTP
High
CVE-2026-41660
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting
High
CVE-2026-35595
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
AVideo: Unauthenticated Live Stream Termination via RTMP Callback on_publish_done.php
High
CVE-2026-34731
was published
for
wwbn/avideo
(Composer)
Apr 1, 2026
AVideo's CSRF on Admin Plugin Configuration Enables Payment Credential Hijacking
High
CVE-2026-34394
was published
for
wwbn/avideo
(Composer)
Mar 31, 2026
AVideo Vulnerable to Reflected XSS via Unsanitized plugin Parameter in YPTWallet Stripe Payment Page
High
CVE-2026-34375
was published
for
wwbn/avideo
(Composer)
Mar 30, 2026
Gokapi has Stored XSS in SVG Hotlinks
High
CVE-2026-28683
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
ProTip!
Advisories are also available from the
GraphQL API