GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
31,590 advisories
Filter by severity
TYPO3 CMS has Broken Access Control in its Form Framework
High
CVE-2026-11607
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in the Recycler Module
Moderate
CVE-2026-47349
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities
Moderate
CVE-2026-47347
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS: Destructive Actions on File Mount Folders
High
CVE-2026-47343
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 HTML Sanitizer allows Cross-site Scripting
Moderate
CVE-2026-47345
was published
for
typo3/html-sanitizer
(Composer)
Jun 12, 2026
PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators
High
GHSA-36hh-v3qg-5jq4
was published
for
pyo3
(Rust)
Jun 12, 2026
TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework
High
CVE-2026-49741
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in its DataHandler
Moderate
CVE-2026-47350
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in its Form Framework
High
CVE-2026-47346
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in its Media Module
High
CVE-2026-49742
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Insecure Deserialization via Core API
Moderate
CVE-2026-49740
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in its File Abstraction Layer
Low
CVE-2026-49738
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in Backend API
Moderate
CVE-2026-47352
was published
for
typo3/cms-backend
(Composer)
Jun 12, 2026
TYPO3 CMS: Broken Access Control in Media Module
Moderate
CVE-2026-47351
was published
for
typo3/cms-backend
(Composer)
Jun 12, 2026
TYPO3 CMS has Cross-Site Scripting in Indexed Search
Moderate
CVE-2026-47348
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 HTML Sanitizer allows Cross-site Scripting
Low
CVE-2026-47344
was published
for
typo3/html-sanitizer
(Composer)
Jun 12, 2026
Tornado has out-of-bounds memory access via C extension
Low
CVE-2026-49854
was published
for
tornado
(pip)
Jun 12, 2026
nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store
Low
GHSA-6vgg-xhvh-38ff
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 12, 2026
pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams
Moderate
CVE-2026-48156
was published
for
pypdf
(pip)
Jun 12, 2026
pypdf: Possible large memory usage for large offsets for layout mode text
Moderate
CVE-2026-48155
was published
for
pypdf
(pip)
Jun 12, 2026
gorest InMemorySecret2FA race condition allows process crash via concurrent map access (CWE-362)
Moderate
CVE-2026-48154
was published
for
github.com/pilinux/gorest
(Go)
Jun 12, 2026
Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation
High
GHSA-j9gf-vw2f-9hrw
was published
for
com.appsmith:server
(Maven)
Jun 12, 2026
Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL
High
CVE-2026-48152
was published
for
@budibase/server
(npm)
Jun 12, 2026
Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
High
CVE-2026-48151
was published
for
@budibase/server
(npm)
Jun 12, 2026
Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
Critical
CVE-2026-48150
was published
for
@budibase/server
(npm)
Jun 12, 2026
ProTip!
Advisories are also available from the
GraphQL API