GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
28,407 advisories
Filter by severity
Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2025-15104
was published
for
nu.validator:validator
(Maven)
Jan 16, 2026
Livewire Filemanager does not restrict uploaded file types
High
CVE-2025-14894
was published
for
livewire-filemanager/filemanager
(Composer)
Jan 16, 2026
Mattermost is vulnerable to DoS due to infinite re-renders on API errors
Moderate
CVE-2025-14435
was published
for
github.com/mattermost/mattermost-server
(Go)
Jan 16, 2026
Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated
High
CVE-2025-68438
was published
for
apache-airflow
(pip)
Jan 16, 2026
Apache Airflow proxy credentials for various providers might leak in task logs
High
CVE-2025-68675
was published
for
apache-airflow
(pip)
Jan 16, 2026
Mattermost is vulnerable to CPU exhaustion via crafted HTTP request
Low
CVE-2025-14822
was published
for
github.com/mattermost/mattermost-server
(Go)
Jan 16, 2026
PlantUML is vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams
Low
CVE-2026-0858
was published
for
net.sourceforge.plantuml:plantuml
(Maven)
Jan 16, 2026
Traefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stall
Moderate
CVE-2026-22045
was published
for
github.com/traefik/traefik/v2
(Go)
Jan 15, 2026
solspace/craft-freeform Exposed to Known Axios Vulnerabilities via Precompiled Assets
Low
GHSA-rwr8-xrpw-9qf5
was published
for
solspace/craft-freeform
(Composer)
Jan 15, 2026
solspace/craft-freeform Vulnerable to XSS in `PhpSpreadsheet` HTML Writer Due to Unsanitized Styling Data
Low
GHSA-44jg-mv3h-wj6g
was published
for
solspace/craft-freeform
(Composer)
Jan 15, 2026
devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse
High
CVE-2026-22775
was published
for
devalue
(npm)
Jan 15, 2026
Vert.x Web static handler component cache can be manipulated to deny the access to static files
Moderate
CVE-2026-1002
was published
for
io.vertx:vertx-core
(Maven)
Jan 15, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication
Moderate
CVE-2025-68671
was published
for
github.com/treeverse/lakefs
(Go)
Jan 15, 2026
Pepr Has Overly Permissive RBAC ClusterRole in Admin Mode
Low
CVE-2026-23634
was published
for
pepr
(npm)
Jan 15, 2026
svelte vulnerable to Cross-site Scripting
Moderate
CVE-2025-15265
was published
for
svelte
(npm)
Jan 15, 2026
solspace/craft-freeform Has a DoS Vulnerability
Low
GHSA-58q2-9x27-h2jm
was published
for
solspace/craft-freeform
(Composer)
Jan 15, 2026
alextselegidis/easyappointments is Vulnerable to CSRF Protection Bypass
High
CVE-2026-23622
was published
for
alextselegidis/easyappointments
(Composer)
Jan 15, 2026
h3 v1 has Request Smuggling (TE.TE) issue
High
CVE-2026-23527
was published
for
h3
(npm)
Jan 15, 2026
Arcane Has a Command Injection in Arcane Updater Lifecycle Labels That Enables RCE
Critical
CVE-2026-23520
was published
for
github.com/getarcaneapp/arcane/backend
(Go)
Jan 15, 2026
Umbraco CMS contains a server-side request forgery vulnerability
Moderate
CVE-2021-47776
was published
for
UmbracoCms
(NuGet)
Jan 15, 2026
Aimeos contains a SQL injection vulnerability in the json api 'sort' parameter
High
CVE-2021-47763
was published
for
aimeos/aimeos-laravel
(Composer)
Jan 15, 2026
RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`
High
CVE-2026-23519
was published
for
cmov
(Rust)
Jan 15, 2026
Zitadel has a user enumeration vulnerability in Login UIs
Moderate
CVE-2026-23511
was published
for
github.com/zitadel/zitadel
(Go)
Jan 15, 2026
Pimcore Web2Print Tools Bundle "Favourite Output Channel Configuration" Missing Function Level Authorization
Moderate
CVE-2026-23496
was published
for
pimcore/web2print-tools-bundle
(Composer)
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
Moderate
CVE-2026-23495
was published
for
pimcore/admin-ui-classic-bundle
(Composer)
Jan 15, 2026
ProTip!
Advisories are also available from the
GraphQL API