GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
391 advisories
Filter by severity
TYPO3 CMS has Broken Access Control in its File Abstraction Layer
Low
CVE-2026-49738
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 HTML Sanitizer allows Cross-site Scripting
Low
CVE-2026-47344
was published
for
typo3/html-sanitizer
(Composer)
Jun 12, 2026
Twig: XSS in profiler HtmlDumper via unescaped template and profile names
Low
CVE-2026-47730
was published
for
twig/twig
(Composer)
Jun 5, 2026
Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames
Low
CVE-2026-48011
was published
for
shopware/core
(Composer)
Jun 4, 2026
symfony/polyfill-intl-idn: xn-- labels with ASCII-only Punycode payloads are treated as equivalent to their decoded form
Low
CVE-2026-46644
was published
for
symfony/polyfill
(Composer)
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
CVE-2026-45756
was published
for
symfony/json-path
(Composer)
May 28, 2026
Symfony's HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/cite — `javascript`: URI Survives Sanitization (XSS)
Low
CVE-2026-45753
was published
for
symfony/html-sanitizer
(Composer)
May 28, 2026
Symfony's YAML Parser has a ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex
Low
CVE-2026-45305
was published
for
symfony/symfony
(Composer)
May 27, 2026
Symfony's YAML Parser Vulnerable to Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")
Low
CVE-2026-45304
was published
for
symfony/symfony
(Composer)
May 27, 2026
Symfony hardened the parser when handling untrusted input
Low
CVE-2026-45133
was published
for
symfony/symfony
(Composer)
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
CVE-2026-45072
was published
for
symfony/symfony
(Composer)
May 27, 2026
Symfony has XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true
Low
CVE-2026-45071
was published
for
symfony/dom-crawler
(Composer)
May 27, 2026
Pterodactyl has a database resource limit bypass via race condition in Client API
Low
CVE-2026-35202
was published
for
pterodactyl/panel
(Composer)
May 26, 2026
Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
Low
CVE-2026-46637
was published
for
twig/cssinliner-extra
(Composer)
May 21, 2026
Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)
Low
CVE-2026-46635
was published
for
twig/twig
(Composer)
May 21, 2026
twig/intl-extra: Unbounded formatter memoisation in keyed on template-controlled arguments
Low
CVE-2026-46629
was published
for
twig/intl-extra
(Composer)
May 21, 2026
Twig: The `spaceless` filter implicitly marks its output as safe
Low
CVE-2026-46628
was published
for
twig/twig
(Composer)
May 21, 2026
Sulu: Used API Keys may be available via Admin API
Low
GHSA-9m6v-8fxc-4r44
was published
for
sulu/sulu
(Composer)
May 18, 2026
LibreNMS: Cross-Site Scripting in ShowConfigController
Low
CVE-2026-2728
was published
for
librenms/librenms
(Composer)
May 18, 2026
Webauthn has a User Verification Downgrade via Default-Open ClientOverridePolicy
Low
GHSA-h4fw-6r7f-w494
was published
for
web-auth/webauthn-framework
(Composer)
May 7, 2026
FacturaScripts vulnerable to Reflected Cross-Site Scripting (XSS) via Cookie Manipulation
Low
CVE-2026-27964
was published
for
facturascripts/facturascripts
(Composer)
May 7, 2026
Grav has Insecure Deserialization in File Cache
Low
CVE-2026-7317
was published
for
getgrav/grav
(Composer)
May 5, 2026
Dolibarr has Insufficient Verification of Data Authenticity
Low
CVE-2026-7689
was published
for
dolibarr/dolibarr
(Composer)
May 3, 2026
Dolibarr has an Injection issue
Low
CVE-2026-7688
was published
for
dolibarr/dolibarr
(Composer)
May 3, 2026
ps_checkout allows unauthorized method invocation through unvalidated parameter
Low
GHSA-mqq7-wxx5-mp8h
was published
for
prestashop/ps_checkout
(Composer)
Apr 30, 2026
ProTip!
Advisories are also available from the
GraphQL API