GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
143,525 advisories
Filter by severity
mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing...
High
Unreviewed
CVE-2026-94112
was published
Sep 20, 2026
Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure...
High
Unreviewed
CVE-2026-94113
was published
Sep 20, 2026
NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi(...
High
Unreviewed
CVE-2026-94104
was published
Sep 20, 2026
getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array...
High
Unreviewed
CVE-2026-94108
was published
Sep 20, 2026
openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker...
High
Unreviewed
CVE-2026-94109
was published
Sep 20, 2026
getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that...
High
Unreviewed
CVE-2026-94106
was published
Sep 20, 2026
The Import and export users and customers WordPress plugin before 2.5.2 does not correctly...
High
Unreviewed
CVE-2026-92540
was published
Sep 20, 2026
The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the...
High
Unreviewed
CVE-2026-92541
was published
Sep 20, 2026
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be...
High
Unreviewed
CVE-2026-87067
was published
Sep 20, 2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly...
High
Unreviewed
CVE-2026-81650
was published
Sep 20, 2026
The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion...
High
Unreviewed
CVE-2026-82842
was published
Sep 20, 2026
The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability...
High
Unreviewed
CVE-2026-85017
was published
Sep 20, 2026
The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not...
High
Unreviewed
CVE-2026-87839
was published
Sep 20, 2026
SmartLife app dynamically generates fresh SmartLife application authentication parameters inside...
High
Unreviewed
CVE-2026-86553
was published
Sep 20, 2026
A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function...
High
Unreviewed
CVE-2026-93958
was published
Sep 20, 2026
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of...
High
Unreviewed
CVE-2026-94054
was published
Sep 20, 2026
Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree...
High
Unreviewed
CVE-2026-93993
was published
Sep 20, 2026
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows...
High
Unreviewed
CVE-2026-94056
was published
Sep 20, 2026
Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input,...
High
Unreviewed
CVE-2026-93990
was published
Sep 20, 2026
Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in...
High
Unreviewed
CVE-2026-93991
was published
Sep 20, 2026
QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin...
High
Unreviewed
CVE-2026-93988
was published
Sep 20, 2026
Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that...
High
Unreviewed
CVE-2026-93992
was published
Sep 20, 2026
The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
High
Unreviewed
CVE-2026-1255
was published
Sep 19, 2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &...
High
Unreviewed
CVE-2026-85658
was published
Sep 19, 2026
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is...
High
Unreviewed
CVE-2026-93742
was published
Sep 19, 2026
ProTip!
Advisories are also available from the
GraphQL API