GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,638
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
658 advisories
Filter by severity
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
High
CVE-2026-78680
was published
for
nltk
(pip)
Sep 1, 2026
Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root,...
High
Unreviewed
CVE-2026-82862
was published
Aug 31, 2026
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative...
High
Unreviewed
CVE-2026-81697
was published
Aug 27, 2026
Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in...
High
Unreviewed
CVE-2026-75768
was published
Aug 25, 2026
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
High
CVE-2026-55522
was published
for
PraisonAI
(pip)
Aug 25, 2026
Duplicate Advisory: Uncontrolled search path when invoking the Graphviz 'dot' binary (CWE-426/CWE-427)
High
GHSA-54xp-3ww7-6wjg
was published
for
nltk
(pip)
Aug 25, 2026
•
withdrawn
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to...
Critical
Unreviewed
CVE-2026-78155
was published
Aug 23, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary...
High
Unreviewed
CVE-2026-16869
was published
Aug 19, 2026
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the...
Critical
Unreviewed
CVE-2026-74872
was published
Aug 17, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
High
Unreviewed
CVE-2026-16674
was published
Aug 13, 2026
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution...
High
Unreviewed
CVE-2026-14875
was published
Aug 13, 2026
Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE...
Low
Unreviewed
CVE-2026-14673
was published
Aug 13, 2026
Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a...
Moderate
Unreviewed
CVE-2026-0299
was published
Aug 13, 2026
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-56174
was published
Aug 11, 2026
Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version...
Moderate
Unreviewed
CVE-2026-32791
was published
Aug 11, 2026
Untrusted search path for some Battery Life Diagnostic Tool software before version 2.9.0 within...
Moderate
Unreviewed
CVE-2026-20799
was published
Aug 11, 2026
FirmaCheck for Windows before 1.3.16 contains a dll hijacking vulnerability that allows local...
High
Unreviewed
CVE-2026-41447
was published
Aug 3, 2026
A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown...
Moderate
Unreviewed
CVE-2026-18605
was published
Aug 3, 2026
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code...
High
Unreviewed
CVE-2026-48391
was published
Jul 28, 2026
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code...
High
Unreviewed
CVE-2026-48395
was published
Jul 28, 2026
AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
High
CVE-2026-11400
was published
for
software.amazon.jdbc:aws-advanced-jdbc-wrapper
(Maven)
Jul 17, 2026
Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote...
High
Unreviewed
CVE-2026-63093
was published
Jul 17, 2026
CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result...
High
Unreviewed
CVE-2026-48287
was published
Jul 15, 2026
Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary...
High
Unreviewed
CVE-2026-48275
was published
Jul 15, 2026
Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code...
High
Unreviewed
CVE-2026-48346
was published
Jul 14, 2026
ProTip!
Advisories are also available from the
GraphQL API