GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,950
Maven
5,000+
npm
4,596
NuGet
787
pip
4,301
Pub
12
RubyGems
982
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
25,938 advisories
Filter by severity
Unauthenticated Spree Commerce users can access all guest addresses
High
CVE-2026-25758
was published
for
spree_api
(RubyGems)
Feb 5, 2026
Unauthenticated Spree Commerce users can view completed guest orders by Order ID
High
CVE-2026-25757
was published
for
spree_storefront
(RubyGems)
Feb 5, 2026
NiceGUI's Path Traversal via Unsanitized FileUpload.name Enables Arbitrary File Write
High
CVE-2026-25732
was published
for
nicegui
(pip)
Feb 5, 2026
@nyariv/sandboxjs has a Sandbox Escape vulnerability
Critical
CVE-2026-25587
was published
for
@nyariv/sandboxjs
(npm)
Feb 5, 2026
@nyariv/sandboxjs has Sandbox Escape via Prototype Whitelist Bypass and Host Prototype Pollution
Critical
CVE-2026-25586
was published
for
@nyariv/sandboxjs
(npm)
Feb 5, 2026
payload-preferences has Cross-Collection IDOR in Access Control (Multi-Auth Environments)
Moderate
CVE-2026-25574
was published
for
payload
(npm)
Feb 5, 2026
@payloadcms/drizzle has SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite Adapters
Critical
CVE-2026-25544
was published
for
@payloadcms/drizzle
(npm)
Feb 5, 2026
@nyariv/sandboxjs has a Sandbox Escape issue
Critical
CVE-2026-25520
was published
for
@nyariv/sandboxjs
(npm)
Feb 5, 2026
OpenCloud Reva has a Public Link Exploit
High
CVE-2026-23989
was published
for
github.com/opencloud-eu/reva/v2
(Go)
Feb 5, 2026
webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior
Low
CVE-2025-68458
was published
for
webpack
(npm)
Feb 5, 2026
webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence
Low
CVE-2025-68157
was published
for
webpack
(npm)
Feb 5, 2026
Microweber has a Cross-site Scripting vulnerability
Low
CVE-2025-70791
was published
for
microweber/microweber
(Composer)
Feb 5, 2026
Microweber Cross-site Scripting vulnerability
Low
CVE-2025-70792
was published
for
microweber/microweber
(Composer)
Feb 5, 2026
pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability
High
CVE-2026-1707
was published
for
pgadmin4
(pip)
Feb 5, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images
Critical
GHSA-x9p2-77v6-6vhf
was published
for
github.com/dunglas/frankenphp
(Go)
Feb 5, 2026
time vulnerable to stack exhaustion Denial of Service attack
Moderate
CVE-2026-25727
was published
for
time
(Rust)
Feb 5, 2026
Sandbox escape via infinite recursion and error objects
Moderate
CVE-2026-25533
was published
for
@enclave-vm/core
(npm)
Feb 5, 2026
NiceGUI's XSS vulnerability in ui.markdown() allows arbitrary JavaScript execution through unsanitized HTML content
Moderate
CVE-2026-25516
was published
for
nicegui
(pip)
Feb 5, 2026
web2py has an Open Redirect Vulnerability
Moderate
CVE-2026-25198
was published
for
web2py
(pip)
Feb 5, 2026
FUXA Unauthenticated Remote Arbitrary Device Tag Write
Critical
CVE-2026-25752
was published
for
fuxa-server
(npm)
Feb 5, 2026
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
Critical
GHSA-88qh-cphv-996c
was published
for
fuxa-server
(npm)
Feb 5, 2026
FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configuration
Critical
GHSA-32cc-x95p-fxcg
was published
for
fuxa-server
(npm)
Feb 5, 2026
FUXA Unauthenticated Exposure of Plaintext Database Credentials
Critical
CVE-2026-25751
was published
for
fuxa-server
(npm)
Feb 5, 2026
FUXA Unauthenticated Remote Code Execution via Admin JWT Minting
Critical
GHSA-vwcg-c828-9822
was published
for
fuxa-server
(npm)
Feb 5, 2026
EVE Has Partially Predetermined Vault Key
Moderate
CVE-2023-43637
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
ProTip!
Advisories are also available from the
GraphQL API