GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,174 advisories
Filter by severity
The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to...
Moderate
Unreviewed
CVE-2026-19225
was published
Aug 27, 2026
Code injection in Bisection in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to...
Moderate
Unreviewed
CVE-2026-79249
was published
Aug 25, 2026
A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the...
Moderate
Unreviewed
CVE-2026-78654
was published
Aug 25, 2026
A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive...
Moderate
Unreviewed
CVE-2026-78181
was published
Aug 24, 2026
A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the...
Moderate
Unreviewed
CVE-2026-78180
was published
Aug 24, 2026
A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability...
Moderate
Unreviewed
CVE-2026-78179
was published
Aug 24, 2026
A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite...
Moderate
Unreviewed
CVE-2026-78178
was published
Aug 24, 2026
The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2026-3424
was published
Aug 22, 2026
n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit...
Moderate
Unreviewed
CVE-2026-77074
was published
Aug 20, 2026
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise...
Moderate
Unreviewed
CVE-2026-13405
was published
Aug 20, 2026
A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject...
Moderate
Unreviewed
CVE-2026-18874
was published
Aug 19, 2026
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
Moderate
CVE-2026-59894
was published
for
sqlparse
(pip)
Aug 17, 2026
The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &...
Moderate
Unreviewed
CVE-2026-18385
was published
Aug 16, 2026
Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to...
Moderate
Unreviewed
CVE-2026-72676
was published
Aug 13, 2026
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP)...
Moderate
Unreviewed
CVE-2026-0298
was published
Aug 13, 2026
An authenticated command injection vulnerability was identified in GMS Command-Line Interface ...
Moderate
Unreviewed
CVE-2026-66148
was published
Aug 11, 2026
An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with...
Moderate
Unreviewed
CVE-2026-18708
was published
Aug 11, 2026
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows...
Moderate
Unreviewed
CVE-2026-65660
was published
Aug 11, 2026
A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their...
Moderate
Unreviewed
CVE-2026-18942
was published
Aug 10, 2026
Mermaid allows CSS injection applying to sibling elements of the diagram
Moderate
CVE-2026-50159
was published
for
mermaid
(npm)
Aug 6, 2026
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
Moderate
CVE-2026-70609
was published
for
electron
(npm)
Aug 5, 2026
Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based)...
Moderate
Unreviewed
CVE-2026-65804
was published
Aug 4, 2026
The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary...
Moderate
Unreviewed
CVE-2025-13146
was published
Jul 22, 2026
TypeORM: migration:generate template-literal code injection
Moderate
CVE-2026-73651
was published
for
typeorm
(npm)
Jul 21, 2026
An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to...
Moderate
Unreviewed
CVE-2026-51385
was published
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API