GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
132 advisories
Filter by severity
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
Moderate
CVE-2026-59894
was published
for
sqlparse
(pip)
Aug 17, 2026
Mermaid allows CSS injection applying to sibling elements of the diagram
Moderate
CVE-2026-50159
was published
for
mermaid
(npm)
Aug 6, 2026
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
Moderate
CVE-2026-70609
was published
for
electron
(npm)
Aug 5, 2026
TypeORM: migration:generate template-literal code injection
Moderate
CVE-2026-73651
was published
for
typeorm
(npm)
Jul 21, 2026
Decidim: HTML content blocks allow stored script execution
Moderate
CVE-2026-45572
was published
for
decidim-core
(RubyGems)
Jul 13, 2026
actual Allows Electron to Run As Node
Moderate
CVE-2026-42890
was published
for
actual
(npm)
Jun 8, 2026
Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API
Moderate
CVE-2026-45719
was published
for
@budibase/server
(npm)
May 18, 2026
Mermaid: Improper sanitization of configuration leads to CSS injection
Moderate
CVE-2026-41159
was published
for
mermaid
(npm)
May 11, 2026
Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection
Moderate
CVE-2026-41149
was published
for
mermaid
(npm)
May 11, 2026
Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection
Moderate
CVE-2026-41148
was published
for
mermaid
(npm)
May 11, 2026
FacturaScripts Vulnerable to Authenticated Remote Code Execution (RCE) via GIF Image Upload in Product Images
Moderate
CVE-2026-42879
was published
for
facturascripts/facturascripts
(Composer)
May 7, 2026
H2O-3 is Vulnerable to Code Injection
Moderate
CVE-2026-3960
was published
for
ai.h2o:h2o-core
(Maven)
Apr 23, 2026
Nuclei: Environment variable disclosure via Response-Derived DSL Expressions
Moderate
CVE-2026-41645
was published
for
github.com/projectdiscovery/nuclei/v3
(Go)
Apr 22, 2026
i18nextify has DOM XSS via javascript:/data: URL schemes in translated href/src attributes
Moderate
CVE-2026-41692
was published
for
i18nextify
(npm)
Apr 22, 2026
Deep Merge is Vulnerable to Prototype Pollution Through Lack of Sanitization
Moderate
CVE-2026-6594
was published
for
@brikcss/merge
(npm)
Apr 20, 2026
Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templates
Moderate
CVE-2026-40602
was published
for
homeassistant-cli
(pip)
Apr 16, 2026
Renovate affected by remote code execution was possible using the bazel-module or bazelisk managers, when using lockFileMaintenance
Moderate
GHSA-5vjq-5jmg-39xq
was published
for
renovate
(npm)
Apr 16, 2026
October Rain has Environment Variable Exfiltration via INI Parser Interpolation
Moderate
CVE-2026-25125
was published
for
october/rain
(Composer)
Apr 14, 2026
FoundationAgents MetaGPT vulnerable to eval injection
Moderate
CVE-2026-5971
was published
for
metagpt
(pip)
Apr 9, 2026
A PinchTab Security Policy Bypass in /wait Allows Arbitrary JavaScript Execution
Moderate
CVE-2026-33622
was published
for
github.com/pinchtab/pinchtab
(Go)
Mar 24, 2026
Craft CMS has Twig Function Blocklist Bypass
Moderate
CVE-2026-28783
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS Vulnerable to Authenticated RCE via Twig SSTI - create() function + Symfony Process gadget
Moderate
CVE-2026-28695
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
OpenClaw: Skill env override host env injection via applySkillConfigEnvOverrides (defense-in-depth)
Moderate
CVE-2026-4039
was published
for
openclaw
(npm)
Feb 27, 2026
ImageMagick: Code Injection via PostScript header in ps coders
Moderate
CVE-2026-25797
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
Apache Avro Java SDK is Vulnerable to Code Injection
Moderate
CVE-2025-33042
was published
for
org.apache.avro:avro-compiler
(Maven)
Feb 13, 2026
ProTip!
Advisories are also available from the
GraphQL API