GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
3,063 advisories
Filter by severity
Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited...
High
Unreviewed
CVE-2026-58572
was published
Sep 1, 2026
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute...
High
Unreviewed
CVE-2026-18729
was published
Aug 29, 2026
BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once...
High
Unreviewed
CVE-2026-82278
was published
Aug 28, 2026
Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that...
High
Unreviewed
CVE-2026-77939
was published
Aug 28, 2026
CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on...
High
Unreviewed
CVE-2026-76148
was published
Aug 28, 2026
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
High
CVE-2026-54757
was published
for
compliance-trestle
(pip)
Aug 28, 2026
ServiceNow has remediated a sandbox escape security issue that was identified in the Now Platform...
High
Unreviewed
CVE-2026-6876
was published
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
High
CVE-2026-54721
was published
for
silverstripe/userforms
(Composer)
Aug 27, 2026
The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network...
High
Unreviewed
CVE-2026-19223
was published
Aug 27, 2026
whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands...
High
Unreviewed
CVE-2026-58474
was published
Aug 26, 2026
The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against...
High
Unreviewed
CVE-2026-74851
was published
Aug 26, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local...
High
Unreviewed
CVE-2026-65082
was published
Aug 25, 2026
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
High
GHSA-vwf3-4xxj-qg6h
was published
for
mcp-contextforge-gateway
(pip)
Aug 25, 2026
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
High
CVE-2026-55585
was published
for
qwed
(pip)
Aug 25, 2026
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
High
CVE-2026-55522
was published
for
PraisonAI
(pip)
Aug 25, 2026
Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling...
High
Unreviewed
CVE-2026-56703
was published
Aug 25, 2026
In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute...
High
Unreviewed
CVE-2025-26238
was published
Aug 24, 2026
AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not...
High
Unreviewed
CVE-2026-76836
was published
Aug 24, 2026
A flaw was found in rpmbuild. When rpmbuild processes a crafted tarball in tarball mode, a...
High
Unreviewed
CVE-2026-78367
was published
Aug 24, 2026
Xinference loads models with Hugging Face remote code execution unconditionally enabled, and...
High
Unreviewed
CVE-2026-76841
was published
Aug 24, 2026
The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other...
High
Unreviewed
CVE-2026-19200
was published
Aug 24, 2026
The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting...
High
Unreviewed
CVE-2026-19221
was published
Aug 22, 2026
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
High
CVE-2026-68508
was published
for
hydra-core
(pip)
Aug 21, 2026
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does...
High
Unreviewed
CVE-2026-18781
was published
Aug 21, 2026
Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability...
High
Unreviewed
CVE-2026-18286
was published
Aug 20, 2026
ProTip!
Advisories are also available from the
GraphQL API