GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
11,179 advisories
Filter by severity
File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection
High
CVE-2026-54090
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jun 12, 2026
File Browser has incorrect access control for public directory shares via rule path rebasing
High
CVE-2026-54091
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser has a DoS Vulnerability via Public Login API
High
CVE-2026-54092
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
High
CVE-2026-54096
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
High
CVE-2026-54097
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY
High
GHSA-gv7w-rqvm-qjhr
was published
for
esbuild
(npm)
Jun 12, 2026
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
High
CVE-2026-53999
was published
for
github.com/radius-project/radius
(Go)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in its Form Framework
High
CVE-2026-11607
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS: Destructive Actions on File Mount Folders
High
CVE-2026-47343
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators
High
GHSA-36hh-v3qg-5jq4
was published
for
pyo3
(Rust)
Jun 12, 2026
TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework
High
CVE-2026-49741
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in its Form Framework
High
CVE-2026-47346
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in its Media Module
High
CVE-2026-49742
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation
High
GHSA-j9gf-vw2f-9hrw
was published
for
com.appsmith:server
(Maven)
Jun 12, 2026
Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL
High
CVE-2026-48152
was published
for
@budibase/server
(npm)
Jun 12, 2026
Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
High
CVE-2026-48151
was published
for
@budibase/server
(npm)
Jun 12, 2026
Appsmith Super User Creation Race Condition Allows Multiple Instance Administrators
High
GHSA-9wcp-79g5-5c3c
was published
for
com.appsmith:server
(Maven)
Jun 12, 2026
GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
High
CVE-2025-52465
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 12, 2026
Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection
High
CVE-2026-48146
was published
for
@budibase/server
(npm)
Jun 12, 2026
SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS
High
CVE-2026-28980
was published
for
github.com/apple/swift-nio
(Swift)
Jun 12, 2026
SwiftNIO: Out-of-bounds write via ByteBuffer index and length UInt32 overflow
High
CVE-2026-43671
was published
for
github.com/apple/swift-nio
(Swift)
Jun 12, 2026
Chisel has an ACL Bypass via Post-Handshake SSH Channel ExtraData Injection
High
CVE-2026-48113
was published
for
github.com/jpillora/chisel
(Go)
Jun 12, 2026
MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
High
CVE-2026-48109
was published
for
MessagePack
(NuGet)
Jun 11, 2026
GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
High
CVE-2025-27511
was published
for
org.geoserver.extension:gs-db2
(Maven)
Jun 11, 2026
Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds
High
CVE-2026-48110
was published
for
russh
(Rust)
Jun 11, 2026
ProTip!
Advisories are also available from the
GraphQL API