GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,683
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,532
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
159 advisories
Filter by severity
Affected devices do not properly sanitize contents of trace files. This could allow an attacker...
Critical
Unreviewed
CVE-2025-40943
was published
Mar 10, 2026
Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
Critical
CVE-2026-33017
was published
for
langflow
(pip)
Mar 17, 2026
The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code...
Critical
Unreviewed
CVE-2026-4001
was published
Mar 24, 2026
GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe...
Critical
Unreviewed
CVE-2026-4851
was published
Mar 29, 2026
TorchGeo Remote Code Execution Vulnerability
High
CVE-2024-49048
was published
for
torchgeo
(pip)
Apr 1, 2026
Agno is vulnerable to Eval Injection
Critical
CVE-2026-35002
was published
for
agno
(pip)
Apr 2, 2026
Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution...
High
Unreviewed
CVE-2026-22666
was published
Apr 7, 2026
An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions...
Moderate
Unreviewed
CVE-2026-4837
was published
Apr 8, 2026
verl's math_equal() Vulnerable to Arbitrary Code Execution via Unsafe eval()
Low
CVE-2026-6878
was published
for
verl
(pip)
Apr 23, 2026
PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope
High
CVE-2026-42079
was published
for
pptagent
(pip)
May 5, 2026
SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code...
Critical
Unreviewed
CVE-2026-44128
was published
May 8, 2026
Angular Expressions - Remote Code Execution using filters
Critical
CVE-2026-44643
was published
for
angular-expressions
(npm)
May 11, 2026
The flash-attention project thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04)...
High
Unreviewed
CVE-2026-31254
was published
May 11, 2026
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an...
High
Unreviewed
CVE-2026-48962
was published
May 27, 2026
Yamcs Vulnerable to Remote Code Execution via Mission Database algorithm override
Critical
CVE-2026-46562
was published
for
org.yamcs:yamcs-core
(Maven)
May 27, 2026
PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution
Critical
CVE-2026-47391
was published
for
PraisonAI
(pip)
May 29, 2026
In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices...
High
Unreviewed
CVE-2026-8914
was published
Jun 5, 2026
Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown...
High
Unreviewed
CVE-2026-50733
was published
Jun 5, 2026
Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection...
High
Unreviewed
CVE-2026-11422
was published
Jun 5, 2026
Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
High
GHSA-cc5p-54x3-hcf8
was published
for
picklescan
(pip)
Jun 17, 2026
•
withdrawn
Karate Mock Server RCE via embedded expression evaluation of request-derived data
High
GHSA-2c85-rfcc-g74j
was published
for
io.karatelabs:karate-core
(Maven)
Jun 18, 2026
python-statemachine SCXML <data expr> Eval Injection
Critical
CVE-2026-47103
was published
for
python-statemachine
(pip)
Jun 18, 2026
xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro
Critical
CVE-2026-44179
was published
for
com.xwiki.pro:xwiki-pro-macros
(Maven)
Jun 22, 2026
Rancher vulnerable to command injection through unsanitized YAML parameter
Critical
CVE-2026-44939
was published
for
github.com/rancher/rancher
(Go)
Jul 1, 2026
EGroupware has Authenticated RCE via Malicious eTemplate Upload
High
CVE-2026-40187
was published
for
egroupware/egroupware
(Composer)
Jul 7, 2026
ProTip!
Advisories are also available from the
GraphQL API