Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,455 advisories

Loading
Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets Moderate
CVE-2026-63179 was published for winter/wn-backend-module (Composer) Aug 20, 2026
hypnguyen1209 Credited to hypnguyen1209
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata Moderate
CVE-2026-54256 was published for winter/wn-backend-module (Composer) Aug 20, 2026
r00tn0b0dy Credited to r00tn0b0dy and baradika baradika baradika
therawdev Credited to therawdev, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
Laravel Backpack CRUD: Stored XSS in the color column — the `@if($column['escaped'])` branches are inverted Moderate
CVE-2026-54181 was published for backpack/crud (Composer) Aug 20, 2026
therawdev Credited to therawdev and tabacitu tabacitu tabacitu
tabacitu Credited to tabacitu
pxpm Credited to pxpm and tabacitu tabacitu tabacitu
therawdev Credited to therawdev, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
therawdev Credited to therawdev, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check Moderate
CVE-2026-54176 was published for backpack/crud (Composer) Aug 20, 2026
pxpm Credited to pxpm and tabacitu tabacitu tabacitu
Laravel Backpack CRUD: Unverified password change in MyAccountController via mass assignment High
CVE-2026-54175 was published for backpack/crud (Composer) Aug 20, 2026
therawdev Credited to therawdev and tabacitu tabacitu tabacitu
Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems High
CVE-2026-62673 was published for getgrav/grav (Composer) Aug 19, 2026
replit-svg Credited to replit-svg
Snipe-IT: Stored DOM XSS via table selected-count IDs Moderate
CVE-2026-61807 was published for snipe/snipe-it (Composer) Aug 19, 2026
Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET Moderate
CVE-2026-55703 was published for snipe/snipe-it (Composer) Aug 19, 2026
SakusenSec Credited to SakusenSec
Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover High
CVE-2026-55694 was published for snipe/snipe-it (Composer) Aug 19, 2026
Rajib-Mahmud Credited to Rajib-Mahmud
Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode High
CVE-2026-55643 was published for snipe/snipe-it (Composer) Aug 19, 2026
Rajib-Mahmud Credited to Rajib-Mahmud
tonghuaroot Credited to tonghuaroot and soyuka soyuka soyuka
LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page High
GHSA-7gww-x7fh-jf9j was published for librenms/librenms (Composer) Aug 18, 2026
k1bana Credited to k1bana
LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users Moderate
GHSA-7cj5-v4pp-v632 was published for librenms/librenms (Composer) Aug 18, 2026
k1bana Credited to k1bana
LibreNMS Vulnerable to Remote Code Execution via AboutController Moderate
GHSA-jf24-8g2h-2wg7 was published for librenms/librenms (Composer) Aug 18, 2026
tCu0n9 Credited to tCu0n9
Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints Critical
CVE-2026-62988 was published for froxlor/froxlor (Composer) Aug 18, 2026
muhammadahmad62 Credited to muhammadahmad62
Froxlor has CSRF Vulnerability in AJAX Endpoint — Missing Cross-Site Request Forgery Protection Moderate
CVE-2026-55593 was published for froxlor/froxlor (Composer) Aug 18, 2026
EclipsSec Credited to EclipsSec
Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields Moderate
CVE-2026-54543 was published for froxlor/froxlor (Composer) Aug 18, 2026
YHalo-wyh Credited to YHalo-wyh
Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltration High
CVE-2026-54348 was published for froxlor/froxlor (Composer) Aug 18, 2026
de3erve Credited to de3erve
Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover High
CVE-2026-54347 was published for froxlor/froxlor (Composer) Aug 18, 2026
de3erve Credited to de3erve
ProTip! Advisories are also available from the GraphQL API