GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,437
Maven
5,000+
npm
5,000+
NuGet
883
pip
4,695
Pub
13
RubyGems
1,031
Rust
1,222
Swift
53
Unreviewed advisories
All unreviewed
5,000+
28,656 advisories
Filter by severity
n8n has Unauthenticated Expression Evaluation via Form Node
Critical
CVE-2026-27493
was published
for
n8n
(npm)
Feb 25, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
Moderate
CVE-2026-25736
was published
for
rucio-webui
(pip)
Feb 25, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
Moderate
CVE-2026-25735
was published
for
rucio-webui
(pip)
Feb 25, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
Moderate
CVE-2026-25734
was published
for
rucio-webui
(pip)
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
High
CVE-2026-3105
was published
for
mautic/core
(Composer)
Feb 25, 2026
ImageMagick has a heap Buffer Over-read in its DJVU image format handler
Moderate
CVE-2026-27799
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
ImageMagick: Heap Buffer Over-read in WaveletDenoise when processing small images
Moderate
CVE-2026-27798
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
hexchat crate has a Use After Free vulnerability
High
GHSA-x43w-ph7m-pfjx
was published
for
hexchat
(Rust)
Feb 25, 2026
CIRCL has an incorrect calculation in secp384r1 CombinedMult
Low
CVE-2026-1229
was published
for
github.com/cloudflare/circl
(Go)
Feb 25, 2026
ImageMagick: Heap-based Buffer Overflow in GetPixelIndex due to metadata-cache desynchronization
Low
GHSA-gq5v-qf8q-fp77
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
ImageMagick: Memory Leak in multiple coders that write raw pixel data
Low
GHSA-wfx3-6g53-9fgc
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
ImageMagick: Memory leak in coders/txt.c without freetype
Low
GHSA-3q5f-gmjc-38r8
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
Low
GHSA-xpg8-7m6m-jf56
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
ImageMagick: Malicious PCD files trigger 1‑byte heap Out-of-bounds Read and DoS
Low
GHSA-wgxp-q8xq-wpp9
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
mageMagick has a possible use-after-free write in its PDB decoder
Low
GHSA-3j4x-rwrx-xxj9
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
ImageMagick has a possible heap Use After Free vulnerability in its meta coder
Low
GHSA-2gq3-ww97-wfjm
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type
Low
GHSA-6j87-m5qx-9fqp
was published
for
craftcms/cms
(Composer)
Feb 25, 2026
changedetection.io is Vulnerable to SSRF via Watch URLs
High
CVE-2026-27696
was published
for
changedetection.io
(pip)
Feb 25, 2026
changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response
Moderate
CVE-2026-27645
was published
for
changedetection.io
(pip)
Feb 25, 2026
Flask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template Injection
Critical
CVE-2026-27641
was published
for
flask-reuploaded
(pip)
Feb 25, 2026
Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessions
High
CVE-2026-27610
was published
for
parse-dashboard
(npm)
Feb 25, 2026
Parse Dashboard is Missing CSRF Protection for its Agent Endpoint
High
CVE-2026-27609
was published
for
parse-dashboard
(npm)
Feb 25, 2026
Parse Dashboard is Missing Authorization for its Agent Endpoint
Critical
CVE-2026-27608
was published
for
parse-dashboard
(npm)
Feb 25, 2026
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
High
CVE-2026-25733
was published
for
rucio-webui
(pip)
Feb 25, 2026
Budibase: Remote Code Execution via Unsafe eval() in View Filter Map Function (Budibase Cloud)
Critical
CVE-2026-27702
was published
for
budibase
(npm)
Feb 25, 2026
ProTip!
Advisories are also available from the
GraphQL API