GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,894
Maven
5,000+
npm
5,000+
NuGet
963
pip
5,000+
Pub
13
RubyGems
1,061
Rust
1,373
Swift
54
Unreviewed advisories
All unreviewed
5,000+
5,855 advisories
Filter by severity
Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
High
CVE-2026-46640
was published
for
twig/twig
(Composer)
May 21, 2026
Twig: Sandbox property and method bypass via object-destructuring assignment
High
CVE-2026-46639
was published
for
twig/twig
(Composer)
May 21, 2026
Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)
Moderate
CVE-2026-46638
was published
for
twig/twig
(Composer)
May 21, 2026
Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
Low
CVE-2026-46637
was published
for
twig/cssinliner-extra
(Composer)
May 21, 2026
Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)
Low
CVE-2026-46635
was published
for
twig/twig
(Composer)
May 21, 2026
Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name
Moderate
CVE-2026-46634
was published
for
twig/twig
(Composer)
May 21, 2026
Twig: PHP code injection via `{% use %}` template name
Critical
CVE-2026-46633
was published
for
twig/twig
(Composer)
May 21, 2026
twig/intl-extra: Unbounded formatter memoisation in keyed on template-controlled arguments
Low
CVE-2026-46629
was published
for
twig/intl-extra
(Composer)
May 21, 2026
Twig: The `spaceless` filter implicitly marks its output as safe
Low
CVE-2026-46628
was published
for
twig/twig
(Composer)
May 21, 2026
phpMyFAQ: Stored XSS via Utils::parseUrl() in comment rendering
High
CVE-2026-46367
was published
for
phpMyFAQ
(Composer)
May 15, 2026
phpMyFAQ: Missing Authorization on Tag Deletion Allows Any Authenticated User to Delete Tags
Moderate
CVE-2026-46365
was published
for
phpMyFAQ/phpMyFAQ
(Composer)
May 15, 2026
phpMyFAQ: Stored XSS in FAQ Question/Answer via Encode-Decode Bypass of removeAttributes() Sanitization
Moderate
CVE-2026-46363
was published
for
phpMyFAQ/phpMyFAQ
(Composer)
May 15, 2026
phpMyFAQ: SVG Sanitizer Entity Decoding Depth Limit Bypass Leading to Stored XSS
Moderate
CVE-2026-46360
was published
for
phpMyFAQ/phpMyFAQ
(Composer)
May 15, 2026
phpMyFAQ: Path traversal in Client::deleteClientFolder enables arbitrary directory deletion by non-super-admin admins
Moderate
CVE-2026-45008
was published
for
phpMyFAQ/phpMyFAQ
(Composer)
May 15, 2026
phpMyFAQ: Ordinary Authenticated User Can Access Admin-Only API Endpoints Due to Insufficient Authorization Check
Moderate
CVE-2026-45009
was published
for
phpMyFAQ/phpMyFAQ
(Composer)
May 15, 2026
Cockpit CMS: Stored cross-site scripting vulnerability in the Set field type's Display template option
Moderate
CVE-2026-23695
was published
for
cockpit-hq/cockpit
(Composer)
May 15, 2026
Snappy: Binary path is never shell-escaped due to an inverted is_executable check
High
CVE-2026-46643
was published
for
KnpLabs/knp-snappy
(Composer)
May 21, 2026
Snappy : SSRF and local file read via the xsl-style-sheet option
Moderate
CVE-2026-46683
was published
for
knplabs/knp-snappy
(Composer)
May 21, 2026
hjson stack exhaustion vulnerability
High
CVE-2023-34620
was published
for
github.com/hjson/hjson-go/v4
(Composer)
Jun 14, 2023
phpMyFAQ: Missing Password Reset Token Allows Account Takeover via Username/Email Enumeration
High
GHSA-w9xh-5f39-vq89
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 20, 2026
phpMyFAQ: Default Empty API Token Authentication Bypass
High
GHSA-gp95-j463-vv28
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 20, 2026
phpMyFAQ: IDOR Account Takeover
High
GHSA-xvp4-phqj-cjr3
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 20, 2026
phpMyFAQ: Unauthenticated Password Reset Endpoint Allows User Enumeration and Forced Password Change Without Token Validation
High
GHSA-9qv9-8xv6-5p35
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 20, 2026
FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service
Moderate
CVE-2026-45802
was published
for
setasign/fpdi
(Composer)
May 19, 2026
AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`
Moderate
CVE-2026-46337
was published
for
WWBN/AVideo
(Composer)
May 19, 2026
ProTip!
Advisories are also available from the
GraphQL API