GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
458 advisories
Filter by severity
GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and...
Moderate
Unreviewed
CVE-2026-56390
was published
Jul 29, 2026
proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An...
Moderate
Unreviewed
CVE-2026-57916
was published
Jul 27, 2026
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
Critical
GHSA-68r5-9hpg-7qw9
was published
for
org.openidentityplatform.opendj:opendj-dsml-servlet
(Maven)
Jul 24, 2026
ImageMagick: Policy Bypass in concatenate operation due to missing checks
Moderate
CVE-2026-55628
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly...
High
Unreviewed
CVE-2026-65896
was published
Jul 23, 2026
LiteLLM: Local file read via request-supplied OIDC file references
Low
CVE-2026-59819
was published
for
litellm
(pip)
Jul 22, 2026
n8n: Edit Image Node Format Injection Allows Arbitrary File Write
High
GHSA-xmc9-4f2h-jf9c
was published
for
n8n
(npm)
Jul 22, 2026
The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions...
High
Unreviewed
CVE-2026-14551
was published
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore
Moderate
CVE-2026-58420
was published
for
gitea.dev
(Go)
Jul 21, 2026
An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 ...
High
Unreviewed
CVE-2026-9587
was published
Jul 17, 2026
The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before...
Moderate
Unreviewed
CVE-2026-12979
was published
Jul 16, 2026
Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process...
High
Unreviewed
CVE-2026-61873
was published
Jul 15, 2026
Improper Restriction of Communication Channel to Intended Endpoints and External Control of File...
High
Unreviewed
CVE-2026-8920
was published
Jul 15, 2026
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode
High
CVE-2026-54629
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
yutu: Arbitrary File Write via MCP `caption-download` Tool
High
CVE-2026-50158
was published
for
github.com/eat-pray-ai/yutu
(Go)
Jul 14, 2026
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode
Critical
CVE-2026-50006
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
External control of file name or path in Windows Ancillary Function Driver for WinSock allows an...
High
Unreviewed
CVE-2026-50462
was published
Jul 14, 2026
External control of file name or path in SQL Server allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-55002
was published
Jul 14, 2026
External control of file name or path in Microsoft Office SharePoint allows an authorized...
Moderate
Unreviewed
CVE-2026-54108
was published
Jul 14, 2026
Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including...
High
Unreviewed
CVE-2026-15736
was published
Jul 14, 2026
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that...
Critical
Unreviewed
CVE-2026-61462
was published
Jul 13, 2026
A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element...
Low
Unreviewed
CVE-2026-15540
was published
Jul 13, 2026
OpenPLC Runtime v3 contains an authenticated arbitrary file write
vulnerability in the legacy...
High
Unreviewed
CVE-2026-14480
was published
Jul 11, 2026
mcp-atlassian: Arbitrary server-side file read via attachment upload
High
GHSA-wm45-qh3g-v83f
was published
for
mcp-atlassian
(pip)
Jul 10, 2026
In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS...
High
Unreviewed
CVE-2026-59793
was published
Jul 10, 2026
ProTip!
Advisories are also available from the
GraphQL API