GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,954
Maven
5,000+
npm
4,606
NuGet
787
pip
4,305
Pub
12
RubyGems
984
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
25,970 advisories
Filter by severity
Cube Core is vulnerable to Denial of Service (DoS) via crafted request
Moderate
CVE-2026-25957
was published
for
@cubejs-backend/server-core
(npm)
Feb 10, 2026
Cube Core is vulnerable to privilege escalation via a specially crafted request
High
CVE-2026-25958
was published
for
@cubejs-backend/server-core
(npm)
Feb 10, 2026
FUXA Affected by a Path Traversal Sanitization Bypass
High
CVE-2026-25951
was published
for
fuxa-server
(npm)
Feb 10, 2026
go-git improperly verifies data integrity values for .idx and .pack files
Moderate
CVE-2026-25934
was published
for
github.com/go-git/go-git/v5
(Go)
Feb 10, 2026
FUXA Unauthenticated Remote Arbitrary Scheduler Write
Critical
CVE-2026-25939
was published
for
fuxa-server
(npm)
Feb 10, 2026
FUXA Unauthenticated Remote Code Execution in Node-RED Integration
Critical
CVE-2026-25938
was published
for
fuxa-server
(npm)
Feb 10, 2026
amphp/http-server affected by HTTP/2 DDoS vulnerability
Moderate
GHSA-8grv-jq2g-cfhw
was published
for
amphp/http-server
(Composer)
Feb 10, 2026
unity-cli Exposes Plaintext Credentials in Debug Logs (sign-package command)
Moderate
CVE-2026-25918
was published
for
@rage-against-the-pixel/unity-cli
(npm)
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
High
CVE-2026-25892
was published
for
vrana/adminer
(Composer)
Feb 10, 2026
File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL
High
CVE-2026-25890
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Feb 10, 2026
@nyariv/sandboxjs has host prototype pollution from sandbox via array intermediary (sandbox escape)
Critical
CVE-2026-25881
was published
for
@nyariv/sandboxjs
(npm)
Feb 10, 2026
File Browser has an Authentication Bypass in User Password Update
Moderate
CVE-2026-25889
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Feb 10, 2026
FroshAdminer Adminer UI is accessible without admin session
Moderate
CVE-2026-25878
was published
for
frosh/adminer-platform
(Composer)
Feb 10, 2026
Bitcoinrb Vulnerable to Command injection via RPC
Low
GHSA-q66h-m87m-j2q6
was published
for
bitcoinrb
(RubyGems)
Feb 10, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
Moderate
CVE-2026-25765
was published
for
faraday
(RubyGems)
Feb 9, 2026
LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
Moderate
CVE-2026-25528
was published
for
langsmith
(npm)
Feb 9, 2026
Craft CMS Vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
High
CVE-2026-25498
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS: GraphQL Asset Mutation Privilege Escalation
High
CVE-2026-25497
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS Vulnerable to Stored XSS in Number Prefix & Suffix Fields
Moderate
CVE-2026-25496
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]`
High
CVE-2026-25495
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via Alternative IP Notation
Moderate
CVE-2026-25494
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via HTTP Redirect
Moderate
CVE-2026-25493
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS: save_images_Asset graphql mutation can be abused to exfiltrate AWS credentials of underlying host
Moderate
CVE-2026-25492
was published
for
craftcms/craft
(Composer)
Feb 9, 2026
Craft CMS Vulnerable to Stored XSS in Entry Types Name
Low
CVE-2026-25491
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Super-linter is vulnerable to command injection via crafted filenames in Super-linter Action
High
CVE-2026-25761
was published
for
super-linter/super-linter
(GitHub Actions)
Feb 9, 2026
ProTip!
Advisories are also available from the
GraphQL API