GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
5,666 advisories
Filter by severity
Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in...
Critical
Unreviewed
CVE-2026-76604
was published
Aug 22, 2026
Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
Critical
Unreviewed
CVE-2026-76605
was published
Aug 22, 2026
The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2026-3424
was published
Aug 22, 2026
The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting...
High
Unreviewed
CVE-2026-19221
was published
Aug 22, 2026
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
Critical
CVE-2026-77415
was published
for
jsonata
(npm)
Aug 21, 2026
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
Critical
CVE-2026-77414
was published
for
jsonata
(npm)
Aug 21, 2026
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
High
CVE-2026-68508
was published
for
hydra-core
(pip)
Aug 21, 2026
JSONata: Arbitrary Code Execution via crafted JSONata expressions
Critical
CVE-2026-77413
was published
for
jsonata
(npm)
Aug 21, 2026
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)
Critical
CVE-2026-59989
was published
for
phalcon/cphalcon
(Composer)
Aug 21, 2026
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as...
Critical
Unreviewed
CVE-2026-77806
was published
Aug 21, 2026
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does...
High
Unreviewed
CVE-2026-18781
was published
Aug 21, 2026
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as...
Critical
Unreviewed
CVE-2026-77647
was published
Aug 21, 2026
Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability...
High
Unreviewed
CVE-2026-18286
was published
Aug 20, 2026
Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerability....
High
Unreviewed
CVE-2026-18287
was published
Aug 20, 2026
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
Critical
Unreviewed
CVE-2026-73992
was published
Aug 20, 2026
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection...
High
Unreviewed
CVE-2026-77075
was published
Aug 20, 2026
n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit...
Moderate
Unreviewed
CVE-2026-77074
was published
Aug 20, 2026
n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox...
High
Unreviewed
CVE-2026-77077
was published
Aug 20, 2026
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise...
Moderate
Unreviewed
CVE-2026-13405
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who...
High
Unreviewed
CVE-2026-76335
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold...
High
Unreviewed
CVE-2026-76314
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold...
High
Unreviewed
CVE-2026-76315
was published
Aug 20, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
High
CVE-2026-53951
was published
for
copier
(pip)
Aug 19, 2026
marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration...
High
Unreviewed
CVE-2026-75149
was published
Aug 19, 2026
A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject...
Moderate
Unreviewed
CVE-2026-18874
was published
Aug 19, 2026
ProTip!
Advisories are also available from the
GraphQL API