GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,437
Maven
5,000+
npm
5,000+
NuGet
883
pip
4,695
Pub
13
RubyGems
1,031
Rust
1,222
Swift
53
Unreviewed advisories
All unreviewed
5,000+
28,656 advisories
Filter by severity
ImageMagick: Out of bounds read in multiple coders read raw pixel data
Moderate
CVE-2026-25576
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick: Infinite loop vulnerability when parsing a PCD file
High
CVE-2026-24485
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick: Converting multi-layer nested MVG to SVG can cause DoS
Moderate
CVE-2026-24484
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick has Possible Heap Information Disclosure in PSD ZIP Decompression
High
CVE-2026-24481
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table
High
CVE-2024-56373
was published
for
apache-airflow
(pip)
Feb 24, 2026
Apache Airflow exposes sensitive information in its log files
Moderate
CVE-2025-27555
was published
for
apache-airflow
(pip)
Feb 24, 2026
Craft CMS Race condition in Token Service potentially allows for token usage greater than the token limit
Moderate
CVE-2026-27128
was published
for
craftcms/cms
(Composer)
Feb 23, 2026
Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS Rebinding
High
CVE-2026-27127
was published
for
craftcms/cms
(Composer)
Feb 23, 2026
Craft CMS has Stored XSS in Table Field via "HTML" Column Type
Moderate
CVE-2026-27126
was published
for
craftcms/cms
(Composer)
Feb 23, 2026
yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
High
CVE-2026-26331
was published
for
yt-dlp
(pip)
Feb 23, 2026
ormar is vulnerable to SQL Injection through aggregate functions min() and max()
Critical
CVE-2026-26198
was published
for
ormar
(pip)
Feb 23, 2026
New API has Potential XSS in its MarkdownRenderer component
High
CVE-2026-25802
was published
for
github.com/QuantumNous/new-api
(Go)
Feb 23, 2026
New API has an SQL LIKE Wildcard Injection DoS via Token Search
High
CVE-2026-25591
was published
for
github.com/QuantumNous/new-api
(Go)
Feb 23, 2026
Astro has Full-Read SSRF in error rendering via Host: header injection
Moderate
CVE-2026-25545
was published
for
@astrojs/node
(npm)
Feb 23, 2026
yapi disables TLS/SSL certificate validation via rejectUnauthorized: false in Axios HTTPS agent
High
CVE-2025-70058
was published
for
yapi-vendor
(npm)
Feb 23, 2026
Apache Camel: KeycloakSecurityPolicy does not validate issuer of JWT tokens against configured realm
Critical
CVE-2026-23552
was published
for
org.apache.camel:camel-keycloak
(Maven)
Feb 23, 2026
Apache Camel Deserializes Untrusted Data in its LevelDB Component
High
CVE-2026-25747
was published
for
org.apache.camel:camel-leveldb
(Maven)
Feb 23, 2026
datapizza-ai has unsafe deserialization via pickle.loads() in RedisCache
Low
CVE-2026-2970
was published
for
datapizza-ai-core
(pip)
Feb 23, 2026
datapizza-ai: Server-Side Template Injection in ChatPromptTemplate via Jinja2 Template Handler
Low
CVE-2026-2969
was published
for
datapizza-ai-core
(pip)
Feb 23, 2026
funadmin: Deserialization Vulnerability in Backend Endpoint via AuthCloudService getMember Function
Low
CVE-2026-2898
was published
for
funadmin/funadmin
(Composer)
Feb 22, 2026
funadmin: XSS through Value argument in Backend Interface component
Low
CVE-2026-2897
was published
for
funadmin/funadmin
(Composer)
Feb 22, 2026
funadmin exposes sensitive information via getMember function
Moderate
CVE-2026-2894
was published
for
funadmin/funadmin
(Composer)
Feb 22, 2026
funadmin has Weak Password Recovery Mechanism for Forgotten Password
Low
CVE-2026-2895
was published
for
funadmin/funadmin
(Composer)
Feb 22, 2026
funadmin has Incorrect Privilege Assignment in its Configuration Handler
Moderate
CVE-2026-2896
was published
for
funadmin/funadmin
(Composer)
Feb 22, 2026
Moodle has a Remote Code Execution risk via file restore
High
CVE-2026-26045
was published
for
moodle/moodle
(Composer)
Feb 21, 2026
ProTip!
Advisories are also available from the
GraphQL API