GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,894
Erlang
38
GitHub Actions
38
Go
2,552
Maven
5,000+
npm
4,224
NuGet
746
pip
3,999
Pub
12
RubyGems
953
Rust
1,041
Swift
45
Unreviewed advisories
All unreviewed
5,000+
519 advisories
Filter by severity
Melis Platform CMS Unauthenticated Admin Account Creation
Critical
CVE-2025-10352
was published
for
melisplatform/melis-core
(Composer)
Oct 8, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
CVE-2025-10353
was published
for
melisplatform/melis-cms-slider
(Composer)
Oct 8, 2025
Melis Platform CMS SQL Injection
Critical
CVE-2025-10351
was published
for
melisplatform/melis-cms
(Composer)
Oct 8, 2025
Magento Community Edition Improper Input Validation vulnerability
Critical
CVE-2025-54236
was published
for
magento/community-edition
(Composer)
Sep 9, 2025
The Freeform CraftCMS plugin contains an Server-side template injection (SSTI) vulnerability
Critical
CVE-2025-52122
was published
for
solspace/craft-freeform
(Composer)
Aug 27, 2025
ThinkPHP Path Traversal Vulnerability
Critical
CVE-2025-50706
was published
for
topthink/framework
(Composer)
Aug 5, 2025
The ADOdb sqlite3 driver allows SQL injection
Critical
CVE-2025-54119
was published
for
adodb/adodb-php
(Composer)
Aug 4, 2025
CodeIgniter4's ImageMagick Handler has Command Injection Vulnerability
Critical
CVE-2025-54418
was published
for
codeigniter4/framework
(Composer)
Jul 28, 2025
nova-tiptap has Unauthenticated Arbitrary File Upload Vulnerability
Critical
CVE-2025-54082
was published
for
manogi/nova-tiptap
(Composer)
Jul 21, 2025
simogeo/filemanager arbitrary file upload vulnerability
Critical
CVE-2025-46001
was published
for
simogeo/filemanager
(Composer)
Jul 18, 2025
Livewire is vulnerable to remote command execution during component property update hydration
Critical
CVE-2025-54068
was published
for
livewire/livewire
(Composer)
Jul 17, 2025
LaRecipe is vulnerable to Server-Side Template Injection attacks
Critical
CVE-2025-53833
was published
for
binarytorch/larecipe
(Composer)
Jul 14, 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
Critical
CVE-2025-49132
was published
for
pterodactyl/panel
(Composer)
Jun 19, 2025
Magneto contains stored XSS vulnerability
Critical
CVE-2025-47110
was published
for
magento/community-edition
(Composer)
Jun 10, 2025
laravel-auth0 SDK Deserialization of Untrusted Data vulnerability
Critical
GHSA-c42h-56wx-h85q
was published
for
auth0/login
(Composer)
Jun 6, 2025
Auth0 Symfony SDK Deserialization of Untrusted Data vulnerability
Critical
GHSA-98j6-67v3-mw34
was published
for
auth0/symfony
(Composer)
Jun 6, 2025
Auth0 Wordpress Plugin vulnerable to Deserialization of Untrusted Data
Critical
GHSA-862m-5253-832r
was published
for
auth0/wordpress
(Composer)
Jun 5, 2025
Auth0-PHP SDK Deserialization of Untrusted Data vulnerability
Critical
CVE-2025-48951
was published
for
auth0/auth0-php
(Composer)
Jun 4, 2025
Roundcube Webmail Vulnerable to Authenticated RCE via PHP Object Deserialization
Critical
CVE-2025-49113
was published
for
roundcube/roundcubemail
(Composer)
Jun 2, 2025
The Front End User Registration extension for TYPO3 (sr_feuser_register) Remote Code Execution
Critical
CVE-2025-48200
was published
for
sjbr/sr-feuser-register
(Composer)
May 21, 2025
laravel-auth0 SDK Vulnerable to Brute Force Authentication Tags of CookieStore Sessions
Critical
GHSA-9fwj-9mjf-rhj3
was published
for
auth0/login
(Composer)
May 17, 2025
Auth0 Wordpress plugin Vulnerable to Brute Force Authentication Tags of CookieStore Sessions
Critical
GHSA-2f4r-34m4-3w8q
was published
for
auth0/wordpress
(Composer)
May 17, 2025
Auth0 Symfony SDK Vulnerable to Brute Force Authentication Tags of CookieStore Sessions
Critical
GHSA-9wg9-93h9-j8ch
was published
for
auth0/symfony
(Composer)
May 17, 2025
Brute Force Authentication Tags of CookieStore Sessions in Auth0-PHP SDK
Critical
CVE-2025-47275
was published
for
auth0/auth0-php
(Composer)
May 16, 2025
SQL injection in ADOdb PostgreSQL driver pg_insert_id() method
Critical
CVE-2025-46337
was published
for
adodb/adodb-php
(Composer)
May 1, 2025
ProTip!
Advisories are also available from the
GraphQL API