GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,954
Maven
5,000+
npm
4,606
NuGet
787
pip
4,305
Pub
12
RubyGems
984
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
1,390 advisories
Filter by severity
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
High
CVE-2026-25892
was published
for
vrana/adminer
(Composer)
Feb 10, 2026
Craft CMS Vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
High
CVE-2026-25498
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS: GraphQL Asset Mutation Privilege Escalation
High
CVE-2026-25497
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]`
High
CVE-2026-25495
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
OpenSTAManager has a SQL Injection in the Prima Nota module
High
CVE-2026-24419
was published
for
devcode-it/openstamanager
(Composer)
Feb 6, 2026
OpenSTAManager has a SQL Injection vulnerability in the Scadenzario bulk operations module
High
CVE-2026-24418
was published
for
devcode-it/openstamanager
(Composer)
Feb 6, 2026
OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service
High
CVE-2026-24417
was published
for
devcode-it/openstamanager
(Composer)
Feb 6, 2026
OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module
High
CVE-2026-24416
was published
for
devcode-it/openstamanager
(Composer)
Feb 6, 2026
OpenSTAManager has a SQL Injection in Scadenzario Print Template
High
CVE-2025-69216
was published
for
devcode-it/openstamanager
(Composer)
Feb 6, 2026
OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint)
High
CVE-2025-69214
was published
for
devcode-it/openstamanager
(Composer)
Feb 6, 2026
OpenSTAManager has an SQL Injection in the Stampe Module
High
CVE-2025-69215
was published
for
devcode-it/openstamanager
(Composer)
Feb 3, 2026
OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint)
High
CVE-2025-69213
was published
for
devcode-it/openstamanager
(Composer)
Feb 3, 2026
FacturaScripts has SQL Injection in Autocomplete Actions
High
CVE-2026-25514
was published
for
facturascripts/facturascripts
(Composer)
Feb 3, 2026
FacturaScripts has SQL Injection in API ORDER BY Clause
High
CVE-2026-25513
was published
for
facturascripts/facturascripts
(Composer)
Feb 3, 2026
Moodle Affected by Improper Restriction of Excessive Authentication Attempts
High
CVE-2025-67853
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle authentication bypass vulnerability
High
CVE-2025-67848
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle Cross-site Scripting (XSS) vulnerability
High
CVE-2025-67849
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle vulnerable to Cross-site Scripting
High
CVE-2025-67850
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
FacturaScripts has Stored Cross-Site Scripting (XSS) in "Observations" field via History View
High
CVE-2026-23997
was published
for
facturascripts/facturascripts
(Composer)
Feb 2, 2026
RaspAP raspap-webgui contains an OS Command Injection vulnerability
High
CVE-2026-24788
was published
for
billz/raspap-webgui
(Composer)
Feb 2, 2026
EGroupware has SQL Injection in Nextmatch Filter Processing
High
CVE-2026-22243
was published
for
egroupware/egroupware
(Composer)
Jan 28, 2026
PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling
High
CVE-2026-24765
was published
for
phpunit/phpunit
(Composer)
Jan 27, 2026
LibreNMS contains an authenticated SQL Injection vulnerability
High
CVE-2020-36947
was published
for
librenms/librenms
(Composer)
Jan 27, 2026
Moodle affected by a code injection vulnerability
High
CVE-2025-67847
was published
for
moodle/moodle
(Composer)
Jan 23, 2026
phpPgAdmin contains a remote command execution vulnerability
High
CVE-2021-47853
was published
for
phppgadmin/phppgadmin
(Composer)
Jan 21, 2026
ProTip!
Advisories are also available from the
GraphQL API