GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
50
GitHub Actions
50
Go
3,673
Maven
5,000+
npm
5,000+
NuGet
932
pip
4,891
Pub
13
RubyGems
1,051
Rust
1,315
Swift
53
Unreviewed advisories
All unreviewed
5,000+
157,012 advisories
Filter by severity
An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in...
Moderate
Unreviewed
CVE-2026-7572
was published
May 6, 2026
An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor...
Moderate
Unreviewed
CVE-2026-7573
was published
May 6, 2026
vLLM Vulnerable to Remote DoS via Special-Token Placeholders
Moderate
CVE-2026-44222
was published
for
vllm
(pip)
May 5, 2026
ciguard: SCA HTTP client reads response body without size cap
Moderate
CVE-2026-44219
was published
for
ciguard
(pip)
May 5, 2026
sse-channel: SSE Injection via unsanitized event fields
Moderate
CVE-2026-44217
was published
for
sse-channel
(npm)
May 5, 2026
AVideo: IDOR in PayPalYPT Plugin Allows Any Authenticated User to Cancel Arbitrary PayPal Subscription Agreements
Moderate
CVE-2026-43883
was published
for
wwbn/avideo
(Composer)
May 5, 2026
AVideo: Unauthenticated CRLF/ICS Injection in Scheduler downloadICS.php Allows Calendar Event Spoofing
Moderate
CVE-2026-43882
was published
for
wwbn/avideo
(Composer)
May 5, 2026
AVideo: Unauthenticated User Enumeration in objects/users.json.php via isCompany Parameter Allows Bypass of the Admin-Only Listing Restriction
Moderate
CVE-2026-43881
was published
for
wwbn/avideo
(Composer)
May 5, 2026
OpAMP client reads unbounded HTTP response bodies
Moderate
CVE-2026-42348
was published
for
OpenTelemetry.OpAmp.Client
(NuGet)
May 5, 2026
AVideo: Unauthenticated Arbitrary Email Sending via sendEmail.json.php Enables Phishing from the Site’s Legitimate From Address
Moderate
CVE-2026-43880
was published
for
wwbn/avideo
(Composer)
May 5, 2026
Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display
Moderate
GHSA-fw8g-cg8f-9j28
was published
for
github.com/prometheus/prometheus
(Go)
May 5, 2026
GraphQL-Ruby's Ruby lexer does not count comment tokens for the purposes of max_query_string_tokens
Moderate
GHSA-3h96-34p3-xm76
was published
for
graphql
(RubyGems)
May 5, 2026
ip-address has XSS in Address6 HTML-emitting methods
Moderate
CVE-2026-42338
was published
for
ip-address
(npm)
May 5, 2026
AVideo has Blind SSRF in YPTWallet Donation Webhook via Missing isSSRFSafeURL() Check and CURLOPT_FOLLOWLOCATION Redirect Bypass
Moderate
CVE-2026-43879
was published
for
wwbn/avideo
(Composer)
May 5, 2026
Kubewarden vulnerable to RBAC Reconnaissance via unchecked can_i host capability call
Moderate
CVE-2026-42541
was published
for
github.com/kubewarden/kubewarden-controller
(Go)
May 5, 2026
Grav is Vulnerable to XXE via SVG Upload
Moderate
GHSA-3446-6mgw-f79p
was published
for
getgrav/grav
(Composer)
May 5, 2026
Dify before version 1.14.0 contains an authorization bypass vulnerability that allows...
Moderate
Unreviewed
CVE-2026-41950
was published
May 5, 2026
Grav Vulnerable to Sensitive Information Disclosure via Accounts Service Bypass
Moderate
CVE-2026-42610
was published
for
getgrav/grav
(Composer)
May 5, 2026
Grav Vulnerable to XSS via Taxonomy Field Values in Admin Panel
Moderate
CVE-2026-42842
was published
for
getgrav/grav
(Composer)
May 5, 2026
Grav CMS vulnerable to stored XSS via Markdown media attribute() action
Moderate
CVE-2026-42841
was published
for
getgrav/grav
(Composer)
May 5, 2026
PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade
Moderate
CVE-2026-44166
was published
for
github.com/pocketbase/pocketbase
(Go)
May 5, 2026
@evomap/evolver has an unbounded request body in proxy /asset/submit that causes persistent disk-exhaustion DoS
Moderate
GHSA-7xp7-m392-h92c
was published
for
@evomap/evolver
(npm)
May 5, 2026
PyLoad Vulnerable to Path Traversal via Package Folder Name
Moderate
CVE-2026-42314
was published
for
pyload-ng
(pip)
May 5, 2026
Ethyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection
Moderate
CVE-2026-42303
was published
for
ethyca-fides
(pip)
May 5, 2026
Kimai vulnerable to formula Injection via tag names in XLSX export
Moderate
CVE-2026-42267
was published
for
kimai/kimai
(Composer)
May 5, 2026
ProTip!
Advisories are also available from the
GraphQL API