GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
762 advisories
Filter by severity
NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
Critical
CVE-2026-79675
was published
for
nltk
(pip)
Sep 1, 2026
Duplicate Advisory: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
Critical
GHSA-3h2g-j4wp-7qqq
was published
for
nltk
(pip)
Aug 25, 2026
•
withdrawn
dash-uploader has a directory traversal vulnerability
Critical
CVE-2026-38360
was published
for
dash-uploader
(pip)
May 8, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
CVE-2026-15925
was published
for
snowflake-connector-python
(pip)
Jul 16, 2026
plone.app.event vulnerable to denial of service via iCalendar import
Critical
CVE-2026-55247
was published
for
plone.app.event
(pip)
Aug 28, 2026
plone.app.portlets vulnerable to denial of service via RSS feed portlet
Critical
CVE-2026-55248
was published
for
plone.app.portlets
(pip)
Aug 28, 2026
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
Critical
CVE-2026-44727
was published
for
jupyter-server
(pip)
Jun 18, 2026
senaite.core Vulnerable to Eval Injection and Missing Authorization
Critical
CVE-2026-54569
was published
for
senaite.core
(pip)
Aug 26, 2026
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
Critical
GHSA-93qj-5q5v-3c2h
was published
for
pantheon-agents
(pip)
Aug 26, 2026
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
Critical
CVE-2026-45018
was published
for
chainlit
(pip)
Aug 25, 2026
nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
Critical
CVE-2026-55640
was published
for
nextcloud-mcp-server
(pip)
Aug 25, 2026
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
Critical
CVE-2026-55546
was published
for
qwed-mcp
(pip)
Aug 25, 2026
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
Critical
CVE-2026-55536
was published
for
PraisonAI
(pip)
Aug 25, 2026
ChromaDB has a code injection vulnerability
Critical
CVE-2026-45833
was published
for
chromadb
(pip)
Jun 12, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
Critical
CVE-2026-61539
was published
for
xinference
(pip)
Aug 21, 2026
ExecuTorch out-of-bounds access vulnerability
Critical
CVE-2025-54950
was published
for
executorch
(Maven)
Aug 8, 2025
ExecuTorch heap buffer overflow vulnerability
Critical
CVE-2025-54949
was published
for
executorch
(Maven)
Aug 8, 2025
ExecuTorch integer overflow vulnerability
Critical
CVE-2025-30404
was published
for
executorch
(Maven)
Aug 8, 2025
ExecuTorch vulnerable to Heap-based Buffer Overflow
Critical
CVE-2025-54951
was published
for
executorch
(Maven)
Aug 8, 2025
ExecuTorch integer overflow vulnerability
Critical
CVE-2025-30405
was published
for
executorch
(Maven)
Aug 8, 2025
surfio has an out-of-bounds read
Critical
CVE-2026-55211
was published
for
surfio
(pip)
Aug 18, 2026
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
Critical
CVE-2026-55209
was published
for
resdata
(pip)
Aug 18, 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
Critical
CVE-2026-64849
was published
for
mlflow
(pip)
Aug 17, 2026
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
Critical
CVE-2026-64825
was published
for
homeassistant
(pip)
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API