GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
72 advisories
Filter by severity
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
Critical
CVE-2026-62379
was published
for
org.openidentityplatform.openam:openam-core
(Maven)
Jul 24, 2026
Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache...
Moderate
Unreviewed
CVE-2026-63317
was published
Jul 24, 2026
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
Moderate
CVE-2026-53666
was published
for
react-router
(npm)
Jul 23, 2026
Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability....
High
Unreviewed
CVE-2026-65608
was published
Jul 23, 2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be...
High
Unreviewed
CVE-2026-13187
was published
Jul 22, 2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence...
High
Unreviewed
CVE-2026-13181
was published
Jul 22, 2026
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution...
High
Unreviewed
CVE-2026-58659
was published
Jul 15, 2026
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability...
Critical
Unreviewed
CVE-2026-40008
was published
Jul 10, 2026
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper...
High
Unreviewed
CVE-2026-24246
was published
Jul 1, 2026
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves...
High
Unreviewed
CVE-2026-13772
was published
Jun 30, 2026
Statamic CMS's unsafe method invocation via collection sorting allows data destruction
High
CVE-2026-49287
was published
for
statamic/cms
(Composer)
Jun 26, 2026
MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments
Moderate
CVE-2026-48517
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
High
CVE-2026-48502
was published
for
MessagePack
(NuGet)
Jun 25, 2026
Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that...
Moderate
Unreviewed
CVE-2026-57284
was published
Jun 24, 2026
Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific types
High
CVE-2026-44795
was published
for
io.spinnaker.orca:orca-core
(Maven)
Jun 22, 2026
Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
Moderate
CVE-2026-48817
was published
for
starlette
(pip)
Jun 15, 2026
Apache Calcite is Vulnerable to Use of Externally-Controlled Input to Select Classes
Moderate
CVE-2026-46718
was published
for
org.apache.calcite:calcite-core
(Maven)
Jun 2, 2026
Yamcs Vulnerable to Remote Code Execution via Mission Database algorithm override
Critical
CVE-2026-46562
was published
for
org.yamcs:yamcs-core
(Maven)
May 27, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
CVE-2026-44174
was published
for
getkirby/cms
(Composer)
May 26, 2026
Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading
Critical
CVE-2026-8178
was published
for
com.amazon.redshift:redshift-jdbc42
(Maven)
May 14, 2026
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
High
CVE-2026-44339
was published
for
PraisonAI
(pip)
May 11, 2026
Craft CMS has Potential Authenticated Remote Code Execution via Malicious Attached Behavior
High
CVE-2026-44011
was published
for
craftcms/cms
(Composer)
May 6, 2026
Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest
Critical
CVE-2026-42027
was published
for
org.apache.opennlp:opennlp-tools
(Maven)
May 4, 2026
Statamic: Unsafe method invocation via query value resolution allows data destruction
High
CVE-2026-41175
was published
for
statamic/cms
(Composer)
Apr 16, 2026
Microsoft Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local...
Moderate
Unreviewed
CVE-2018-25239
was published
Apr 4, 2026
ProTip!
Advisories are also available from the
GraphQL API