GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,867
Maven
5,000+
npm
4,488
NuGet
780
pip
4,244
Pub
12
RubyGems
975
Rust
1,096
Swift
49
Unreviewed advisories
All unreviewed
5,000+
25,585 advisories
Filter by severity
phpMyFAQ: Public API endpoints expose emails and invisible questions
Moderate
CVE-2026-24422
was published
for
phpmyfaq/phpmyfaq
(Composer)
Jan 23, 2026
phpMyFAQ: /api/setup/backup accessible to any authenticated user (authz missing)
Moderate
CVE-2026-24421
was published
for
phpmyfaq/phpmyfaq
(Composer)
Jan 23, 2026
phpMyFAQ: Attachment download allowed without dlattachment right (broken access control)
Moderate
CVE-2026-24420
was published
for
phpmyfaq/phpmyfaq
(Composer)
Jan 23, 2026
LavaLite CMS affected by a stored cross-site scripting vulnerability
Moderate
CVE-2025-71177
was published
for
lavalite/cms
(Composer)
Jan 23, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Moderate
CVE-2025-67124
was published
for
miniserve
(Rust)
Jan 23, 2026
CometBFT has inconsistencies between how commit signatures are verified and how block time is derived
High
GHSA-c32p-wcqj-j677
was published
for
github.com/cometbft/cometbft
(Go)
Jan 23, 2026
XWiki Affected by Reflected Cross-Site Scripting (XSS) in Error Messages
Moderate
CVE-2026-24128
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Jan 23, 2026
protobuf affected by a JSON recursion depth bypass
High
CVE-2026-0994
was published
for
protobuf
(pip)
Jan 23, 2026
Moodle affected by a code injection vulnerability
High
CVE-2025-67847
was published
for
moodle/moodle
(Composer)
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Moderate
CVE-2026-20904
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Moderate
CVE-2026-20912
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea may send release notification emails for private repositories to users whose access has been revoked
Low
CVE-2026-0798
was published
for
code.gitea.io/gitea
(Go)
Jan 23, 2026
Gitea has improper access control for uploaded attachments
Low
CVE-2026-20736
was published
for
code.gitea.io/gitea
(Go)
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
CVE-2026-20800
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Moderate
CVE-2026-20750
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Moderate
CVE-2026-20888
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
CVE-2026-20883
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Moderate
CVE-2026-20897
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Container and Containerization archive extraction does not guard against escapes from extraction base directory.
Low
CVE-2026-20613
was published
for
github.com/apple/container
(Swift)
Jan 22, 2026
Freeform Craft Plugin CP UI (builder/integrations) has Stored Cross-Site Scripting (XSS) issue
Low
GHSA-jp3q-wwp3-pwv9
was published
for
solspace/craft-freeform
(Composer)
Jan 22, 2026
Spring Security has a broken timing attack mitigation implemented in DaoAuthenticationProvide
Moderate
CVE-2025-22234
was published
for
org.springframework.security:spring-security-core
(Maven)
Jan 22, 2026
sigstore legacy TUF client allows for arbitrary file writes with target cache path traversal
Moderate
CVE-2026-24137
was published
for
github.com/sigstore/sigstore
(Go)
Jan 22, 2026
Incus container image templating arbitrary host file read and write
High
CVE-2026-23954
was published
for
github.com/lxc/incus/v6/cmd/incusd
(Go)
Jan 22, 2026
Incus container environment configuration newline injection
High
CVE-2026-23953
was published
for
github.com/lxc/incus/v6
(Go)
Jan 22, 2026
Rekor affected by Server-Side Request Forgery (SSRF) via provided public key URL
Moderate
CVE-2026-24117
was published
for
github.com/sigstore/rekor
(Go)
Jan 22, 2026
ProTip!
Advisories are also available from the
GraphQL API