GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
52 advisories
Filter by severity
Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox,...
Low
Unreviewed
CVE-2026-80201
was published
Aug 31, 2026
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
Low
CVE-2026-59821
was published
for
litellm
(pip)
Jul 22, 2026
A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This...
Low
Unreviewed
CVE-2026-16008
was published
Jul 17, 2026
A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function...
Low
Unreviewed
CVE-2026-15702
was published
Jul 14, 2026
A vulnerability was determined in kofrasa mingo up to 7.2.1. This impacts the function update...
Low
Unreviewed
CVE-2026-15698
was published
Jul 14, 2026
A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget...
Low
Unreviewed
CVE-2026-15697
was published
Jul 14, 2026
A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the...
Low
Unreviewed
CVE-2026-15699
was published
Jul 14, 2026
A vulnerability was detected in tanstack db up to 0.6.8. Affected by this vulnerability is the...
Low
Unreviewed
CVE-2026-15607
was published
Jul 14, 2026
A weakness has been identified in apidevtools json-schema-ref-parser up to 15.3.5. This impacts...
Low
Unreviewed
CVE-2026-15195
was published
Jul 9, 2026
A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer...
Low
Unreviewed
CVE-2026-15187
was published
Jul 9, 2026
A vulnerability in Wikimedia Foundation timeline.
This vulnerability is associated with program...
Low
Unreviewed
CVE-2026-8857
was published
Jul 1, 2026
OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source
Low
GHSA-9wxg-vf3r-56hc
was published
for
@openzeppelin/wizard
(npm)
Jun 19, 2026
SAP Landscape Transformation contains a vulnerability in an RFC-exposed function module that...
Low
Unreviewed
CVE-2026-27675
was published
Apr 14, 2026
An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a...
Low
Unreviewed
CVE-2023-31044
was published
Mar 3, 2026
A vulnerability was identified in higuma web-audio-recorder-js 0.1/0.1.1. Impacted is the...
Low
Unreviewed
CVE-2026-2964
was published
Feb 23, 2026
OpenClaw Affected by Remote Code Execution via System Prompt Injection in Slack Channel Descriptions
Low
CVE-2026-24764
was published
for
openclaw
(npm)
Feb 17, 2026
Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board...
Low
Unreviewed
CVE-2025-58827
was published
Sep 5, 2025
A flaw was found in GLib. A denial of service on Windows platforms may occur if an application...
Low
Unreviewed
CVE-2025-4056
was published
Jul 28, 2025
Aim Vulnerable to Sandbox Escape Leading to Remote Code Execution
Low
CVE-2025-5321
was published
for
aim
(pip)
May 29, 2025
Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper...
Low
Unreviewed
CVE-2025-23376
was published
Apr 28, 2025
Apereo CAS code injection vulnerability
Low
CVE-2025-3984
was published
for
org.apereo.cas:cas-management-webapp-support
(Maven)
Apr 27, 2025
Apache Kylin Code Injection via JDBC Configuration Alteration
Low
CVE-2025-30067
was published
for
org.apache.kylin:kylin
(Maven)
Mar 27, 2025
A vulnerability, which was classified as problematic, was found in lmxcms 1.41. Affected is an...
Low
Unreviewed
CVE-2025-1465
was published
Feb 19, 2025
An error related to the 2-factor authorization (2FA) on the RISC Platform prior to the saas-2021...
Low
Unreviewed
CVE-2021-41527
was published
Feb 7, 2025
ProTip!
Advisories are also available from the
GraphQL API