GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,951
Maven
5,000+
npm
4,598
NuGet
787
pip
4,305
Pub
12
RubyGems
983
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
9,051 advisories
Filter by severity
Craft CMS Vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
High
CVE-2026-25498
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS: GraphQL Asset Mutation Privilege Escalation
High
CVE-2026-25497
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]`
High
CVE-2026-25495
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Super-linter is vulnerable to command injection via crafted filenames in Super-linter Action
High
CVE-2026-25761
was published
for
super-linter/super-linter
(GitHub Actions)
Feb 9, 2026
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
High
CVE-2026-25639
was published
for
axios
(npm)
Feb 9, 2026
Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins
High
CVE-2026-25478
was published
for
litestar
(pip)
Feb 9, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service
High
CVE-2026-25791
was published
for
github.com/bishopfox/sliver
(Go)
Feb 6, 2026
Antrea has invalid enforcement order for network policy rules caused by integer overflow
High
CVE-2026-25804
was published
for
antrea.io/antrea
(Go)
Feb 6, 2026
Blocklist Bypass possible via ECDSA Signature Malleability
High
CVE-2026-25793
was published
for
github.com/slackhq/nebula
(Go)
Feb 6, 2026
AdonisJS vulnerable to Denial of Service (DoS) via Unrestricted Memory Buffering in PartHandler during File Type Detection
High
CVE-2026-25762
was published
for
@adonisjs/bodyparser
(npm)
Feb 6, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams
High
GHSA-26gq-grmh-6xm6
was published
for
gogs.io/gogs
(Go)
Feb 6, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
High
GHSA-w67g-2h6v-vjgq
was published
for
phlex
(RubyGems)
Feb 6, 2026
AdonisJS multipart body parsing has Prototype Pollution issue
High
CVE-2026-25754
was published
for
@adonisjs/bodyparser
(npm)
Feb 6, 2026
Claude Code has Sandbox Escape via Persistent Configuration Injection in settings.json
High
CVE-2026-25725
was published
for
@anthropic-ai/claude-code
(npm)
Feb 6, 2026
Claude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write Restrictions
High
CVE-2026-25723
was published
for
@anthropic-ai/claude-code
(npm)
Feb 6, 2026
Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protection
High
CVE-2026-25722
was published
for
@anthropic-ai/claude-code
(npm)
Feb 6, 2026
MCP-Salesforce's arbitrary attribute access leads to disclosure of Salesforce auth token
High
CVE-2026-25650
was published
for
mcp-salesforce-connector
(pip)
Feb 6, 2026
Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL
High
CVE-2026-25640
was published
for
pydantic-ai
(pip)
Feb 6, 2026
Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling
High
CVE-2026-25580
was published
for
pydantic-ai
(pip)
Feb 6, 2026
Mattermost Confluence plugin doesn't properly escape user-controlled display names in HTML template rendering
High
CVE-2025-13523
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Feb 6, 2026
OpenSTAManager has a SQL Injection in the Prima Nota module
High
CVE-2026-24419
was published
for
devcode-it/openstamanager
(Composer)
Feb 6, 2026
OpenSTAManager has a SQL Injection vulnerability in the Scadenzario bulk operations module
High
CVE-2026-24418
was published
for
devcode-it/openstamanager
(Composer)
Feb 6, 2026
OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service
High
CVE-2026-24417
was published
for
devcode-it/openstamanager
(Composer)
Feb 6, 2026
OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module
High
CVE-2026-24416
was published
for
devcode-it/openstamanager
(Composer)
Feb 6, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update
High
CVE-2026-24135
was published
for
gogs.io/gogs
(Go)
Feb 6, 2026
ProTip!
Advisories are also available from the
GraphQL API