GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
35,755 advisories
Filter by severity
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
High
CVE-2026-33625
was published
for
lmdeploy
(pip)
Sep 18, 2026
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
Critical
CVE-2025-66455
was published
for
lmdeploy
(pip)
Sep 18, 2026
Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks
High
GHSA-jr78-w6w5-m8f8
was published
for
mediawiki/semantic-media-wiki
(Composer)
Sep 18, 2026
Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)
Moderate
GHSA-9rcc-pmj8-ffhr
was published
for
mediawiki/semantic-media-wiki
(Composer)
Sep 18, 2026
Semantic MediaWiki affected by reflected XSS in `Special:Ask` via a forged cursor pagination token
Moderate
CVE-2026-77616
was published
for
mediawiki/semantic-media-wiki
(Composer)
Sep 18, 2026
Semantic MediaWiki has a query debug output XSS (`DebugFormatter`)
Moderate
CVE-2026-77610
was published
for
mediawiki/semantic-media-wiki
(Composer)
Sep 18, 2026
Semantic MediaWiki has an open redirect in Special:URIResolver
Moderate
CVE-2026-77609
was published
for
mediawiki/semantic-media-wiki
(Composer)
Sep 18, 2026
Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSS
Moderate
CVE-2026-77607
was published
for
mediawiki/semantic-media-wiki
(Composer)
Sep 18, 2026
Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property` and `value` parameters)
Moderate
CVE-2026-77608
was published
for
mediawiki/semantic-media-wiki
(Composer)
Sep 18, 2026
Semantic MediaWiki has reflected XSS in Special:Ask plain table headers
Moderate
CVE-2026-77606
was published
for
mediawiki/semantic-media-wiki
(Composer)
Sep 18, 2026
Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes
High
CVE-2025-61682
was published
for
mediawiki/semantic-media-wiki
(Composer)
Sep 18, 2026
org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue
Critical
CVE-2025-53837
was published
for
org.xwiki.rendering:xwiki-rendering-xml
(Maven)
Sep 18, 2026
Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text
High
CVE-2026-77615
was published
for
org.opencastproject:opencast-engage-paella-player-7
(Maven)
Sep 18, 2026
Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass
Moderate
CVE-2026-77281
was published
for
github.com/caddyserver/caddy/v2
(Go)
Sep 18, 2026
Grav CMS vulnerable to remote code execution via .zip file upload
High
CVE-2026-72819
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin
High
CVE-2026-75837
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate
Moderate
CVE-2026-75834
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Blueprint dynamic-data bare-function branch is denylist-gated and omits error_log, giving arbitrary file write
Critical
CVE-2026-75827
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS
Critical
CVE-2026-75828
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)
High
CVE-2026-74907
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion
High
CVE-2026-72695
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP
High
CVE-2026-86003
was published
for
github.com/coredns/coredns
(Go)
Sep 17, 2026
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns
Moderate
CVE-2026-86000
was published
for
soupsieve
(pip)
Sep 17, 2026
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)
Moderate
CVE-2026-85999
was published
for
soupsieve
(pip)
Sep 17, 2026
ProTip!
Advisories are also available from the
GraphQL API