GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
188 advisories
Filter by severity
MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets
Moderate
CVE-2026-55855
was published
for
mariadb
(npm)
Aug 28, 2026
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output
Moderate
CVE-2026-55859
was published
for
org.mariadb:r2dbc-mariadb
(Maven)
Aug 28, 2026
NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker...
Moderate
Unreviewed
CVE-2026-65085
was published
Aug 25, 2026
eml_parser has a URL extraction bypass via HTML entities in URLs
Moderate
CVE-2026-55618
was published
for
eml_parser
(pip)
Aug 25, 2026
Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username
Moderate
CVE-2026-63466
was published
for
unleash-server
(npm)
Aug 21, 2026
Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock...
Moderate
Unreviewed
CVE-2026-61399
was published
Aug 21, 2026
Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header...
Moderate
Unreviewed
CVE-2026-43971
was published
Aug 18, 2026
dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting...
Moderate
Unreviewed
CVE-2026-73479
was published
Aug 14, 2026
gdu fails to strip terminal escape sequences from directory and file names when printing paths...
Moderate
Unreviewed
CVE-2026-73480
was published
Aug 13, 2026
is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a...
Moderate
Unreviewed
CVE-2026-48376
was published
Aug 11, 2026
GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing...
Moderate
Unreviewed
CVE-2026-66486
was published
Aug 10, 2026
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
Moderate
CVE-2026-70609
was published
for
electron
(npm)
Aug 5, 2026
CentreStack before 17.4 contains a session variable injection vulnerability that allows...
Moderate
Unreviewed
CVE-2026-54364
was published
Jul 30, 2026
mathlive's Lack of Escaping of HTML allows for XSS
Moderate
CVE-2026-54705
was published
for
mathlive
(npm)
Jul 29, 2026
diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting...
Moderate
Unreviewed
CVE-2026-50642
was published
Jul 29, 2026
Shescape: Home-directory disclosure in assignment context on Unix with Dash
Moderate
CVE-2026-73411
was published
for
shescape
(npm)
Jul 24, 2026
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
Moderate
GHSA-hc76-7mpc-qjqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
Moderate
CVE-2026-64647
was published
for
next
(npm)
Jul 22, 2026
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
Moderate
CVE-2026-59895
was published
for
hono
(npm)
Jul 21, 2026
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
Moderate
CVE-2026-50659
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization
Moderate
CVE-2026-49844
was published
for
org.apache.logging.log4j:log4j-api
(Maven)
Jul 11, 2026
YesWiki has stored XSS in Bazar form-field templates via unescaped field.label / field.hint (|raw('html'))
Moderate
CVE-2026-52772
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)
Moderate
CVE-2026-35366
was published
for
uu_printenv
(Rust)
Jul 6, 2026
justhtml: to_markdown() code-span blank-line breakout enables XSS
Moderate
GHSA-jf6w-2mvx-633j
was published
for
justhtml
(pip)
Jun 25, 2026
Improper escaping of database table names in the CaptureChangeMySQL Processor included with...
Moderate
Unreviewed
CVE-2026-44913
was published
Jun 22, 2026
ProTip!
Advisories are also available from the
GraphQL API