GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,936
Maven
5,000+
npm
4,590
NuGet
787
pip
4,298
Pub
12
RubyGems
981
Rust
1,116
Swift
49
Unreviewed advisories
All unreviewed
5,000+
5,202 advisories
Filter by severity
OpenSTAManager has a SQL Injection in the Prima Nota module
High
CVE-2026-24419
was published
for
devcode-it/openstamanager
(Composer)
Feb 6, 2026
OpenSTAManager has a SQL Injection vulnerability in the Scadenzario bulk operations module
High
CVE-2026-24418
was published
for
devcode-it/openstamanager
(Composer)
Feb 6, 2026
OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service
High
CVE-2026-24417
was published
for
devcode-it/openstamanager
(Composer)
Feb 6, 2026
OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module
High
CVE-2026-24416
was published
for
devcode-it/openstamanager
(Composer)
Feb 6, 2026
OpenSTAManager has a SQL Injection in Scadenzario Print Template
High
CVE-2025-69216
was published
for
devcode-it/openstamanager
(Composer)
Feb 6, 2026
OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint)
High
CVE-2025-69214
was published
for
devcode-it/openstamanager
(Composer)
Feb 6, 2026
OpenSTAManager has an OS Command Injection in P7M File Processing
Critical
CVE-2025-69212
was published
for
devcode-it/openstamanager
(Composer)
Feb 6, 2026
Microweber has a Cross-site Scripting vulnerability
Low
CVE-2025-70791
was published
for
microweber/microweber
(Composer)
Feb 5, 2026
Microweber Cross-site Scripting vulnerability
Low
CVE-2025-70792
was published
for
microweber/microweber
(Composer)
Feb 5, 2026
Winter CMS has Stored Cross-site Scripting (XSS) in Asset Manager
Low
CVE-2026-22254
was published
for
winter/wn-cms-module
(Composer)
Feb 4, 2026
PrestaShop affected by time based enumeration in FO login form
Moderate
CVE-2026-25597
was published
for
prestashop/prestashop
(Composer)
Feb 3, 2026
OpenSTAManager has an SQL Injection in the Stampe Module
High
CVE-2025-69215
was published
for
devcode-it/openstamanager
(Composer)
Feb 3, 2026
OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint)
High
CVE-2025-69213
was published
for
devcode-it/openstamanager
(Composer)
Feb 3, 2026
FacturaScripts has SQL Injection in Autocomplete Actions
High
CVE-2026-25514
was published
for
facturascripts/facturascripts
(Composer)
Feb 3, 2026
FacturaScripts has SQL Injection in API ORDER BY Clause
High
CVE-2026-25513
was published
for
facturascripts/facturascripts
(Composer)
Feb 3, 2026
Moodle Inserts Sensitive Information Into Sent Data
Moderate
CVE-2025-67857
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle has an authorization logic flaw
Moderate
CVE-2025-67856
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle Open Redirect vulnerability
Low
CVE-2025-67852
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle vulnerable to Cross-site Scripting
Moderate
CVE-2025-67855
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle Affected by Improper Restriction of Excessive Authentication Attempts
High
CVE-2025-67853
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle Cross-site Scripting (XSS) vulnerability
High
CVE-2025-67849
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle formula injection vulnerability
Moderate
CVE-2025-67851
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle vulnerable to Cross-site Scripting
High
CVE-2025-67850
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle authentication bypass vulnerability
High
CVE-2025-67848
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Subrion CMS vulnerable to cross-site scripting
Moderate
CVE-2025-70958
was published
for
intelliants/subrion
(Composer)
Feb 3, 2026
ProTip!
Advisories are also available from the
GraphQL API