GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,762
Maven
5,000+
npm
4,371
NuGet
767
pip
4,141
Pub
12
RubyGems
962
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
5,090 advisories
Filter by severity
AWS SDK for PHP's S3 Encryption Client has a Key Commitment Issue
Moderate
CVE-2025-14761
was published
for
aws/aws-sdk-php
(Composer)
Dec 18, 2025
Auth0 WordPress has Improper Audience Validation via Auth0-PHP SDK Dependency
Moderate
GHSA-vvg7-8rmq-92g7
was published
for
auth0/wordpress
(Composer)
Dec 17, 2025
Auth0 Symfony SDK has Improper Audience Validation via Auth0-PHP SDK
Moderate
GHSA-f3r2-88mq-9v4g
was published
for
auth0/symfony
(Composer)
Dec 17, 2025
Auth0 Laravel SDK has Improper Audience Validation via Auth0-PHP SDK dependency
Moderate
GHSA-7hh9-gp72-wh7h
was published
for
auth0/login
(Composer)
Dec 17, 2025
Auth0-PHP SDK has Improper Audience Validation
Moderate
CVE-2025-68129
was published
for
auth0/auth0-php
(Composer)
Dec 17, 2025
Pagekit CMS has an Insecure Direct Object Reference (IDOR) in its User Role component
Critical
CVE-2025-67165
was published
for
pagekit/pagekit
(Composer)
Dec 17, 2025
Pagekit CMS is vulnerable to OS Command Injection via Storage component
Critical
CVE-2025-67164
was published
for
pagekit/pagekit
(Composer)
Dec 17, 2025
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
Moderate
CVE-2025-68113
was published
for
altcha
(RubyGems)
Dec 16, 2025
Grav is vulnerable to Stored XSS through authenticated user-edited content
Moderate
CVE-2025-66843
was published
for
getgrav/grav
(Composer)
Dec 15, 2025
Grav may be vulnerable to SSRF attack via Twig Templates
Critical
CVE-2025-66844
was published
for
getgrav/grav
(Composer)
Dec 15, 2025
MineAdmin has an insecure default password
Critical
CVE-2025-65854
was published
for
mineadmin/mineadmin
(Composer)
Dec 12, 2025
FoF Pretty Mail has a server-side template injection vulnerability
High
CVE-2024-58303
was published
for
fof/pretty-mail
(Composer)
Dec 12, 2025
AzuraCast Vulnerable to Pre-Auth File Deletion & Admin RCE
Low
CVE-2025-67737
was published
for
azuracast/azuracast
(Composer)
Dec 11, 2025
Ibexa User Bundle is missing password change validation
Critical
CVE-2025-67719
was published
for
ibexa/user
(Composer)
Dec 10, 2025
Shopware Storefront Reflected XSS in Storefront Login Page
High
CVE-2025-67648
was published
for
shopware/shopware
(Composer)
Dec 9, 2025
SAML PHP Toolkit Vulnerability on xmlseclibs CVE-2025-66475
Critical
GHSA-5j8p-438x-rgg5
was published
for
onelogin/php-saml
(Composer)
Dec 9, 2025
Neuron MySQLWriteTool allows arbitrary/destructive SQL when exposed to untrusted prompts (agent “footgun”)
Critical
CVE-2025-67510
was published
for
neuron-core/neuron-ai
(Composer)
Dec 9, 2025
Neuron MySQLSelectTool “read-only” bypass via `SELECT ... INTO OUTFILE` (file write → potential RCE)
High
CVE-2025-67509
was published
for
neuron-core/neuron-ai
(Composer)
Dec 9, 2025
Filament multi-factor authentication (app) recovery codes can be used multiple times
High
CVE-2025-67507
was published
for
filament/filament
(Composer)
Dec 9, 2025
robrichards/xmlseclibs has an Libxml2 Canonicalization error which can bypass Digest/Signature validation
Moderate
CVE-2025-66578
was published
for
robrichards/xmlseclibs
(Composer)
Dec 8, 2025
alexusmai laravel-file-manager is vulnerable to Directory Traversal via the unzip/extraction functionality
High
CVE-2025-65346
was published
for
alexusmai/laravel-file-manager
(Composer)
Dec 4, 2025
alexusmai laravel-file-manager is vulnerable to Directory Traversal
Low
CVE-2025-65345
was published
for
alexusmai/laravel-file-manager
(Composer)
Dec 3, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
High
CVE-2025-66468
was published
for
aimeos/ai-cms-grapesjs
(Composer)
Dec 3, 2025
FeehiCMS Has a Remote Code Execution via Unrestricted File Upload in Ad Management
Moderate
CVE-2025-65657
was published
for
feehi/cms
(Composer)
Dec 2, 2025
GrapesJsBuilder File Upload allows all file uploads
High
CVE-2025-13827
was published
for
mautic/grapes-js-builder-bundle
(Composer)
Dec 2, 2025
ProTip!
Advisories are also available from the
GraphQL API