GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,683
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,532
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
159 advisories
Filter by severity
Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator
Critical
CVE-2026-71867
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli
Critical
CVE-2026-71865
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client
Critical
CVE-2026-71864
was published
for
orval
(npm)
Sep 3, 2026
n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free...
High
Unreviewed
CVE-2026-85165
was published
Sep 3, 2026
Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client
Critical
CVE-2026-71866
was published
for
orval
(npm)
Sep 2, 2026
Faker: helpers.fake exploitable into arbritary code execution
High
CVE-2026-73231
was published
for
@faker-js/faker
(npm)
Sep 2, 2026
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute...
High
Unreviewed
CVE-2026-65643
was published
Sep 1, 2026
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary...
Critical
Unreviewed
CVE-2026-19295
was published
Aug 29, 2026
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the...
Critical
Unreviewed
CVE-2026-75062
was published
Aug 26, 2026
senaite.core Vulnerable to Eval Injection and Missing Authorization
Critical
CVE-2026-54569
was published
for
senaite.core
(pip)
Aug 26, 2026
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in...
High
Unreviewed
CVE-2026-78136
was published
Aug 23, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
Critical
CVE-2026-61539
was published
for
xinference
(pip)
Aug 21, 2026
@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers...
High
Unreviewed
CVE-2026-76833
was published
Aug 20, 2026
Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to...
Moderate
Unreviewed
CVE-2026-74234
was published
Aug 17, 2026
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in...
Critical
Unreviewed
CVE-2026-74899
was published
Aug 17, 2026
A remote code execution vulnerability exists in Tenable Security Center's report generation...
Critical
Unreviewed
CVE-2026-19626
was published
Aug 14, 2026
Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP...
Critical
Unreviewed
CVE-2026-73601
was published
Aug 13, 2026
Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that...
Critical
Unreviewed
CVE-2026-73602
was published
Aug 13, 2026
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
Critical
CVE-2026-69264
was published
for
flowise
(npm)
Aug 4, 2026
Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated...
High
Unreviewed
CVE-2026-67195
was published
Aug 4, 2026
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in...
Critical
Unreviewed
CVE-2026-48317
was published
Aug 4, 2026
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category...
Critical
Unreviewed
CVE-2026-39932
was published
Aug 3, 2026
SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for...
Critical
Unreviewed
CVE-2026-15971
was published
Jul 30, 2026
AWS Amplify Studio UI Component Properties Has an Input Validation Issue
Critical
CVE-2025-4318
was published
for
@aws-amplify/codegen-ui-react
(npm)
Jul 30, 2026
ProTip!
Advisories are also available from the
GraphQL API