GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,683
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,532
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
3,070 advisories
Filter by severity
n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the ...
High
Unreviewed
CVE-2026-85169
was published
Sep 3, 2026
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
High
CVE-2026-62675
was published
for
omnigent
(pip)
Sep 2, 2026
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their...
High
Unreviewed
CVE-2026-84645
was published
Sep 2, 2026
Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()
High
CVE-2026-64850
was published
for
getgrav/grav
(Composer)
Sep 2, 2026
pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install
High
CVE-2026-82393
was published
for
pnpm
(npm)
Sep 2, 2026
An eval() injection vulnerability in the get_list function in modules/meta_parser.py in...
High
Unreviewed
CVE-2026-51974
was published
Sep 1, 2026
Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited...
High
Unreviewed
CVE-2026-58572
was published
Sep 1, 2026
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute...
High
Unreviewed
CVE-2026-18729
was published
Aug 29, 2026
BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once...
High
Unreviewed
CVE-2026-82278
was published
Aug 28, 2026
Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that...
High
Unreviewed
CVE-2026-77939
was published
Aug 28, 2026
CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on...
High
Unreviewed
CVE-2026-76148
was published
Aug 28, 2026
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
High
CVE-2026-54757
was published
for
compliance-trestle
(pip)
Aug 28, 2026
ServiceNow has remediated a sandbox escape security issue that was identified in the Now Platform...
High
Unreviewed
CVE-2026-6876
was published
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
High
CVE-2026-54721
was published
for
silverstripe/userforms
(Composer)
Aug 27, 2026
The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network...
High
Unreviewed
CVE-2026-19223
was published
Aug 27, 2026
whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands...
High
Unreviewed
CVE-2026-58474
was published
Aug 26, 2026
The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against...
High
Unreviewed
CVE-2026-74851
was published
Aug 26, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local...
High
Unreviewed
CVE-2026-65082
was published
Aug 25, 2026
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
High
GHSA-vwf3-4xxj-qg6h
was published
for
mcp-contextforge-gateway
(pip)
Aug 25, 2026
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
High
CVE-2026-55585
was published
for
qwed
(pip)
Aug 25, 2026
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
High
CVE-2026-55522
was published
for
PraisonAI
(pip)
Aug 25, 2026
Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling...
High
Unreviewed
CVE-2026-56703
was published
Aug 25, 2026
In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute...
High
Unreviewed
CVE-2025-26238
was published
Aug 24, 2026
AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not...
High
Unreviewed
CVE-2026-76836
was published
Aug 24, 2026
A flaw was found in rpmbuild. When rpmbuild processes a crafted tarball in tarball mode, a...
High
Unreviewed
CVE-2026-78367
was published
Aug 24, 2026
ProTip!
Advisories are also available from the
GraphQL API