GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
5,658 advisories
Filter by severity
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data...
Critical
Unreviewed
CVE-2026-75827
was published
Aug 18, 2026
A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine...
Critical
Unreviewed
CVE-2026-38165
was published
Aug 18, 2026
An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox...
High
Unreviewed
CVE-2026-67961
was published
Aug 18, 2026
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint...
Critical
Unreviewed
CVE-2026-67919
was published
Aug 18, 2026
An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the...
Critical
Unreviewed
CVE-2026-67960
was published
Aug 18, 2026
An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files...
Critical
Unreviewed
CVE-2026-67926
was published
Aug 17, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11,...
Critical
Unreviewed
CVE-2026-19478
was published
Aug 17, 2026
Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input...
Critical
Unreviewed
CVE-2026-74253
was published
Aug 17, 2026
An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code...
Critical
Unreviewed
CVE-2026-50772
was published
Aug 17, 2026
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
Moderate
CVE-2026-59894
was published
for
sqlparse
(pip)
Aug 17, 2026
The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &...
Moderate
Unreviewed
CVE-2026-18385
was published
Aug 16, 2026
The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code...
High
Unreviewed
CVE-2026-17581
was published
Aug 16, 2026
ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module...
High
Unreviewed
CVE-2026-73679
was published
Aug 14, 2026
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code...
Critical
Unreviewed
CVE-2026-73678
was published
Aug 14, 2026
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions...
High
Unreviewed
CVE-2026-19768
was published
Aug 14, 2026
Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin...
High
Unreviewed
CVE-2026-72819
was published
Aug 14, 2026
Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to...
Moderate
Unreviewed
CVE-2026-72676
was published
Aug 13, 2026
amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby...
High
Unreviewed
CVE-2026-67986
was published
Aug 13, 2026
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
Critical
Unreviewed
CVE-2026-61962
was published
Aug 13, 2026
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
Critical
Unreviewed
CVE-2026-27544
was published
Aug 13, 2026
Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable...
Critical
Unreviewed
CVE-2026-73487
was published
Aug 13, 2026
Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that...
Critical
Unreviewed
CVE-2026-73485
was published
Aug 13, 2026
Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's...
Critical
Unreviewed
CVE-2026-73486
was published
Aug 13, 2026
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP)...
Moderate
Unreviewed
CVE-2026-0298
was published
Aug 13, 2026
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution...
High
Unreviewed
CVE-2026-13094
was published
Aug 12, 2026
ProTip!
Advisories are also available from the
GraphQL API