GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
3,704 advisories
Filter by severity
Logging operator has Fluentd configuration injection that allows remote code execution
Critical
CVE-2026-54680
was published
for
github.com/kube-logging/logging-operator
(Go)
Jul 29, 2026
cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover...
High
Unreviewed
CVE-2024-58354
was published
Jul 24, 2026
A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected...
Low
Unreviewed
CVE-2026-16763
was published
Jul 24, 2026
A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element...
Low
Unreviewed
CVE-2026-16733
was published
Jul 23, 2026
A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1....
Low
Unreviewed
CVE-2026-16735
was published
Jul 23, 2026
A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec...
Low
Unreviewed
CVE-2026-16631
was published
Jul 23, 2026
A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the...
Low
Unreviewed
CVE-2026-16628
was published
Jul 23, 2026
A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger...
Moderate
Unreviewed
CVE-2026-16629
was published
Jul 23, 2026
A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3....
Low
Unreviewed
CVE-2026-16630
was published
Jul 23, 2026
A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function...
Low
Unreviewed
CVE-2026-16492
was published
Jul 22, 2026
A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function...
Low
Unreviewed
CVE-2026-16489
was published
Jul 22, 2026
A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the...
Low
Unreviewed
CVE-2026-16488
was published
Jul 22, 2026
A vulnerability in the command line interface of ECOS devices could allow a highly privileged,...
High
Unreviewed
CVE-2026-44879
was published
Jul 21, 2026
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
High
GHSA-956x-8gvw-wg5v
was published
for
GitPython
(pip)
Jul 21, 2026
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can...
Low
Unreviewed
CVE-2026-59846
was published
Jul 21, 2026
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table...
Critical
Unreviewed
CVE-2025-71392
was published
Jul 18, 2026
An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute...
Critical
Unreviewed
CVE-2026-52199
was published
Jul 17, 2026
An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a...
Critical
Unreviewed
CVE-2025-65720
was published
Jul 16, 2026
LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation...
Critical
Unreviewed
CVE-2026-30623
was published
Jul 16, 2026
LangBot: Authenticated RCE Via MCP Configuration
High
CVE-2026-54449
was published
for
langbot
(pip)
Jul 15, 2026
Improper neutralization of special elements used in a command ('command injection') in Windows...
High
Unreviewed
CVE-2026-56197
was published
Jul 14, 2026
Improper neutralization of special elements used in a command ('command injection') in Outlook...
Moderate
Unreviewed
CVE-2026-55145
was published
Jul 14, 2026
Improper neutralization of special elements used in a command ('command injection') in Windows...
High
Unreviewed
CVE-2026-50488
was published
Jul 14, 2026
Improper neutralization of special elements used in a command ('command injection') in Windows...
High
Unreviewed
CVE-2026-58635
was published
Jul 14, 2026
Improper neutralization of special elements used in a command ('command injection') in Visual...
High
Unreviewed
CVE-2026-50520
was published
Jul 14, 2026
ProTip!
Advisories are also available from the
GraphQL API