GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
9,515 advisories
Filter by severity
The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file...
Critical
Unreviewed
CVE-2026-78657
was published
Sep 2, 2026
The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to...
High
Unreviewed
CVE-2026-14982
was published
Sep 2, 2026
A vulnerability was identified in MapQuest Get Directions App 10.16.1 on Android. This...
Low
Unreviewed
CVE-2026-84442
was published
Sep 2, 2026
A security vulnerability has been detected in Piwigo up to 16.3.0. Affected by this issue is some...
Moderate
Unreviewed
CVE-2026-84441
was published
Sep 2, 2026
A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the...
Low
Unreviewed
CVE-2026-84431
was published
Sep 2, 2026
facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing...
High
Unreviewed
CVE-2026-84702
was published
Sep 2, 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana...
High
Unreviewed
CVE-2026-78592
was published
Sep 1, 2026
An unauthenticated path traversal vulnerability exists in the API endpoint of HPE Networking...
Moderate
Unreviewed
CVE-2026-73737
was published
Sep 1, 2026
pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project
High
GHSA-2rx9-3g3h-c2jv
was published
for
pnpm
(npm)
Sep 1, 2026
appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and...
Moderate
Unreviewed
CVE-2026-84201
was published
Sep 1, 2026
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization...
High
Unreviewed
CVE-2026-61753
was published
Sep 1, 2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion...
High
Unreviewed
CVE-2026-19952
was published
Sep 1, 2026
A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality...
Moderate
Unreviewed
CVE-2026-67395
was published
Sep 1, 2026
A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function...
High
Unreviewed
CVE-2026-82954
was published
Sep 1, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
CVE-2026-75594
was published
for
getkirby/cms
(Composer)
Aug 31, 2026
A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read...
High
Unreviewed
CVE-2026-79407
was published
Aug 31, 2026
In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change...
High
Unreviewed
CVE-2026-82217
was published
Aug 31, 2026
ILIAS versions before 9.22, 10.0 through 10.9, and 11.0 through 11.2 contain an arbitrary file...
High
Unreviewed
CVE-2026-82877
was published
Aug 31, 2026
Improper validation of resource URL attributes in Apache Wicket allows an unauthenticated remote...
Moderate
Unreviewed
CVE-2026-70449
was published
Aug 31, 2026
A vulnerability was detected in yaojingang GEOFlow up to 2.1.0. This vulnerability affects the...
Low
Unreviewed
CVE-2026-82665
was published
Aug 31, 2026
A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the...
Low
Unreviewed
CVE-2026-82599
was published
Aug 31, 2026
A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of...
Low
Unreviewed
CVE-2026-82603
was published
Aug 31, 2026
AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability...
High
Unreviewed
CVE-2026-56718
was published
Aug 30, 2026
Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality,...
Low
Unreviewed
CVE-2026-82656
was published
Aug 30, 2026
Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command...
High
Unreviewed
CVE-2026-82635
was published
Aug 30, 2026
ProTip!
Advisories are also available from the
GraphQL API