GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
412 advisories
Filter by severity
MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets
Moderate
CVE-2026-55855
was published
for
mariadb
(npm)
Aug 28, 2026
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output
Moderate
CVE-2026-55859
was published
for
org.mariadb:r2dbc-mariadb
(Maven)
Aug 28, 2026
PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI
Low
CVE-2026-55891
was published
for
privatebin/privatebin
(Composer)
Aug 28, 2026
gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to...
Low
Unreviewed
CVE-2026-82249
was published
Aug 28, 2026
openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI,...
Critical
Unreviewed
CVE-2026-81685
was published
Aug 27, 2026
NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker...
Moderate
Unreviewed
CVE-2026-65085
was published
Aug 25, 2026
eml_parser has a URL extraction bypass via HTML entities in URLs
Moderate
CVE-2026-55618
was published
for
eml_parser
(pip)
Aug 25, 2026
Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors
High
CVE-2026-61824
was published
for
defuddle
(npm)
Aug 21, 2026
Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username
Moderate
CVE-2026-63466
was published
for
unleash-server
(npm)
Aug 21, 2026
Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using...
Critical
Unreviewed
CVE-2026-61398
was published
Aug 21, 2026
Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock...
Moderate
Unreviewed
CVE-2026-61399
was published
Aug 21, 2026
Laravel Backpack CRUD: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)
High
CVE-2026-54182
was published
for
backpack/crud
(Composer)
Aug 20, 2026
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25...
High
Unreviewed
CVE-2025-36254
was published
Aug 20, 2026
jmespath.php has CompilerRuntime code injection via unescaped function names
Critical
CVE-2026-54133
was published
for
mtdowling/jmespath.php
(Composer)
Aug 18, 2026
Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header...
Moderate
Unreviewed
CVE-2026-43971
was published
Aug 18, 2026
Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in...
Critical
Unreviewed
CVE-2026-73055
was published
Aug 16, 2026
dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting...
Moderate
Unreviewed
CVE-2026-73479
was published
Aug 14, 2026
gdu fails to strip terminal escape sequences from directory and file names when printing paths...
Moderate
Unreviewed
CVE-2026-73480
was published
Aug 13, 2026
HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient...
Low
Unreviewed
CVE-2025-62315
was published
Aug 13, 2026
is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a...
Moderate
Unreviewed
CVE-2026-48376
was published
Aug 11, 2026
GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing...
Moderate
Unreviewed
CVE-2026-66486
was published
Aug 10, 2026
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
Moderate
CVE-2026-70609
was published
for
electron
(npm)
Aug 5, 2026
CentreStack before 17.4 contains a session variable injection vulnerability that allows...
Moderate
Unreviewed
CVE-2026-54364
was published
Jul 30, 2026
mathlive's Lack of Escaping of HTML allows for XSS
Moderate
CVE-2026-54705
was published
for
mathlive
(npm)
Jul 29, 2026
diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting...
Moderate
Unreviewed
CVE-2026-50642
was published
Jul 29, 2026
ProTip!
Advisories are also available from the
GraphQL API