GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
5,666 advisories
Filter by severity
In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering...
Critical
Unreviewed
CVE-2026-75414
was published
Aug 26, 2026
A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component...
Critical
Unreviewed
CVE-2026-52103
was published
Aug 26, 2026
whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands...
High
Unreviewed
CVE-2026-58474
was published
Aug 26, 2026
The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against...
High
Unreviewed
CVE-2026-74851
was published
Aug 26, 2026
Code injection in Bisection in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to...
Moderate
Unreviewed
CVE-2026-79249
was published
Aug 25, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local...
High
Unreviewed
CVE-2026-65082
was published
Aug 25, 2026
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
High
GHSA-vwf3-4xxj-qg6h
was published
for
mcp-contextforge-gateway
(pip)
Aug 25, 2026
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
High
CVE-2026-55585
was published
for
qwed
(pip)
Aug 25, 2026
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
Critical
CVE-2026-55546
was published
for
qwed-mcp
(pip)
Aug 25, 2026
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
High
CVE-2026-55522
was published
for
PraisonAI
(pip)
Aug 25, 2026
A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on...
Critical
Unreviewed
CVE-2026-57909
was published
Aug 25, 2026
SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1...
Critical
Unreviewed
CVE-2026-49845
was published
Aug 25, 2026
A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the...
Moderate
Unreviewed
CVE-2026-78654
was published
Aug 25, 2026
Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling...
High
Unreviewed
CVE-2026-56703
was published
Aug 25, 2026
An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute...
Critical
Unreviewed
CVE-2026-52490
was published
Aug 24, 2026
In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute...
High
Unreviewed
CVE-2025-26238
was published
Aug 24, 2026
AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not...
High
Unreviewed
CVE-2026-76836
was published
Aug 24, 2026
A flaw was found in rpmbuild. When rpmbuild processes a crafted tarball in tarball mode, a...
High
Unreviewed
CVE-2026-78367
was published
Aug 24, 2026
Xinference loads models with Hugging Face remote code execution unconditionally enabled, and...
High
Unreviewed
CVE-2026-76841
was published
Aug 24, 2026
The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other...
High
Unreviewed
CVE-2026-19200
was published
Aug 24, 2026
A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive...
Moderate
Unreviewed
CVE-2026-78181
was published
Aug 24, 2026
A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the...
Moderate
Unreviewed
CVE-2026-78180
was published
Aug 24, 2026
A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability...
Moderate
Unreviewed
CVE-2026-78179
was published
Aug 24, 2026
A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite...
Moderate
Unreviewed
CVE-2026-78178
was published
Aug 24, 2026
Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7...
Critical
Unreviewed
CVE-2026-77992
was published
Aug 22, 2026
ProTip!
Advisories are also available from the
GraphQL API