GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,460
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,142
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
5,065 advisories
Filter by severity
Logging operator has Fluentd configuration injection that allows remote code execution
Critical
CVE-2026-54680
was published
for
github.com/kube-logging/logging-operator
(Go)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
High
CVE-2026-54666
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped enum string values
High
CVE-2026-54664
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
High
CVE-2026-54661
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
High
CVE-2026-54662
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0...
Moderate
Unreviewed
CVE-2026-18085
was published
Jul 28, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
High
CVE-2026-55404
was published
for
yt-dlp
(pip)
Jul 24, 2026
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
High
GHSA-3rp5-jjmw-4wv2
was published
for
gitpython
(pip)
Jul 24, 2026
A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some...
Moderate
Unreviewed
CVE-2026-16765
was published
Jul 24, 2026
A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Impacted is...
Low
Unreviewed
CVE-2026-16490
was published
Jul 22, 2026
A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this...
Moderate
Unreviewed
CVE-2026-16484
was published
Jul 22, 2026
A vulnerability was determined in zsadmin2025 ZS-Admin up to...
Low
Unreviewed
CVE-2026-16449
was published
Jul 21, 2026
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW,...
Low
Unreviewed
CVE-2026-16448
was published
Jul 21, 2026
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability...
Low
Unreviewed
CVE-2026-16334
was published
Jul 21, 2026
A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated...
Moderate
Unreviewed
CVE-2026-16252
was published
Jul 20, 2026
A security vulnerability has been detected in itsourcecode Hospital Management System 1.0....
Low
Unreviewed
CVE-2026-16244
was published
Jul 20, 2026
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1...
Moderate
Unreviewed
CVE-2026-16227
was published
Jul 19, 2026
A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is...
Moderate
Unreviewed
CVE-2026-16228
was published
Jul 19, 2026
A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This affects the function...
Low
Unreviewed
CVE-2026-16204
was published
Jul 19, 2026
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php....
Moderate
Unreviewed
CVE-2026-16154
was published
Jul 18, 2026
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an...
Moderate
Unreviewed
CVE-2026-16152
was published
Jul 18, 2026
A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an...
Low
Unreviewed
CVE-2026-16131
was published
Jul 18, 2026
A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the...
Low
Unreviewed
CVE-2026-16133
was published
Jul 18, 2026
oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code
Low
GHSA-rjwr-m7qx-3fjr
was published
for
github.com/oapi-codegen/oapi-codegen/v2
(Go)
Jul 17, 2026
A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an...
Moderate
Unreviewed
CVE-2026-16014
was published
Jul 17, 2026
ProTip!
Advisories are also available from the
GraphQL API