GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
192 advisories
Filter by severity
TensorZero Gateway: Arbitrary file read and SSRF in internal object storage endpoint
High
CVE-2026-54457
was published
for
tensorzero
(pip)
Jul 15, 2026
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode
High
CVE-2026-54629
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
repomix contains a local file inclusion vulnerability in the git clone endpoint that allows...
High
Unreviewed
CVE-2026-59703
was published
Jul 8, 2026
GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user...
High
Unreviewed
CVE-2025-66389
was published
Jun 22, 2026
Files or directories accessible to external parties vulnerability in ABB T-MAC Plus.
This issue...
High
Unreviewed
CVE-2025-14771
was published
Jun 3, 2026
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a...
High
Unreviewed
CVE-2024-56462
was published
May 27, 2026
An authenticated attacker with the Resource Administrator or Administrator role can modify...
High
Unreviewed
CVE-2026-40631
was published
May 13, 2026
Dalfox Server Mode has an Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file`
High
CVE-2026-45088
was published
for
github.com/hahwul/dalfox/v2
(Go)
May 12, 2026
A path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15...
High
Unreviewed
CVE-2026-39871
was published
May 11, 2026
pgAdmin 4 contains local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities
High
CVE-2026-7817
was published
for
pgadmin4
(pip)
May 11, 2026
A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its...
High
Unreviewed
CVE-2025-7389
was published
Apr 14, 2026
OpenClaw: Self-Whitelisting in appendLocalMediaParentRoots Allows Arbitrary File Read & Credential Exfiltration
High
GHSA-57gh-m6rq-54cf
was published
for
openclaw
(npm)
Apr 3, 2026
From
Panorama Web HMI, an attacker can gain read access to certain Web HMI server
files, if he...
High
Unreviewed
CVE-2026-4760
was published
Mar 25, 2026
ZKTeco ZKAccess Professional 3.5.3 contains an insecure file permissions vulnerability that...
High
Unreviewed
CVE-2016-20025
was published
Mar 16, 2026
EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated...
High
Unreviewed
CVE-2018-25164
was published
Mar 6, 2026
webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers...
High
Unreviewed
CVE-2020-37082
was published
Feb 4, 2026
Arbitrary file deletion vulnerability have been identified in a system function of mobility...
High
Unreviewed
CVE-2025-37168
was published
Jan 13, 2026
Picklescan vulnerable to Arbitrary File Writing
High
CVE-2025-71321
was published
for
picklescan
(pip)
Dec 29, 2025
V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure...
High
Unreviewed
CVE-2019-25239
was published
Dec 24, 2025
Microhard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows...
High
Unreviewed
CVE-2018-25145
was published
Dec 24, 2025
due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and...
High
Unreviewed
CVE-2025-14896
was published
Dec 18, 2025
Constellation has insecure LUKS2 persistent storage partitions which may be opened and used
High
CVE-2025-58356
was published
for
github.com/edgelesssys/constellation/v2
(Go)
Oct 27, 2025
An arbitrary file download vulnerability in the web interface of Juniper Networks Junos Space...
High
Unreviewed
CVE-2025-59976
was published
Oct 9, 2025
Apache Kylin Files or Directories Accessible to External Parties
High
CVE-2025-61734
was published
for
org.apache.kylin:kylin
(Maven)
Oct 2, 2025
Elevation of Privileges in the cleaning feature of Gen Digital CCleaner version 6.33.11465 on...
High
Unreviewed
CVE-2025-3025
was published
Sep 15, 2025
ProTip!
Advisories are also available from the
GraphQL API