GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
30 advisories
Filter by severity
Faker: helpers.fake exploitable into arbritary code execution
High
CVE-2026-73231
was published
for
@faker-js/faker
(npm)
Sep 2, 2026
NLTK vulnerable to Eval Injection via collocations CLI arguments
High
CVE-2025-71408
was published
for
nltk
(pip)
Jul 25, 2026
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
High
CVE-2026-55415
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
High
CVE-2026-45293
was published
for
wp-coding-standards/wpcs
(Composer)
Jul 28, 2026
Picklescan has a missing detection when calling built-in python idlelib.calltip.Calltip
High
CVE-2025-71361
was published
for
picklescan
(pip)
Aug 26, 2025
django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization
High
GHSA-r3hx-x5rh-p9vv
was published
for
django-haystack
(pip)
Jul 15, 2026
MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php
High
CVE-2026-49273
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
EGroupware has Authenticated RCE via Malicious eTemplate Upload
High
CVE-2026-40187
was published
for
egroupware/egroupware
(Composer)
Jul 7, 2026
Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
High
GHSA-cc5p-54x3-hcf8
was published
for
picklescan
(pip)
Jun 17, 2026
•
withdrawn
Karate Mock Server RCE via embedded expression evaluation of request-derived data
High
GHSA-2c85-rfcc-g74j
was published
for
io.karatelabs:karate-core
(Maven)
Jun 18, 2026
PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope
High
CVE-2026-42079
was published
for
pptagent
(pip)
May 5, 2026
TorchGeo Remote Code Execution Vulnerability
High
CVE-2024-49048
was published
for
torchgeo
(pip)
Apr 1, 2026
locutus call_user_func_array vulnerable to Remote Code Execution (RCE) due to Code Injection
High
CVE-2026-29091
was published
for
locutus
(npm)
Mar 4, 2026
XWiki vulnerable to remote code execution through insufficient protection against {{/html}} injection
High
CVE-2025-66474
was published
for
org.xwiki.rendering:xwiki-rendering-xml
(Maven)
Dec 10, 2025
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
High
CVE-2025-64496
was published
for
open-webui
(npm)
Nov 7, 2025
XWiki Blog Application: Privilege Escalation (PR) from account through blog content
High
CVE-2025-58365
was published
for
org.xwiki.contrib.blog:application-blog-ui
(Maven)
Sep 8, 2025
Refuel Autolab Eval Injection vulnerability
High
CVE-2024-27320
was published
for
refuel-autolabel
(pip)
Sep 12, 2024
Refuel Autolab Eval Injection vulnerability
High
CVE-2024-27321
was published
for
refuel-autolabel
(pip)
Sep 12, 2024
Guardrails has an arbitrary code execution vulnerability
High
CVE-2024-45858
was published
for
guardrails-ai
(pip)
Sep 18, 2024
MindsDB Eval Injection vulnerability
High
CVE-2024-45851
was published
for
mindsdb
(pip)
Sep 12, 2024
MindsDB Eval Injection vulnerability
High
CVE-2024-45850
was published
for
mindsdb
(pip)
Sep 12, 2024
MindsDB Eval Injection vulnerability
High
CVE-2024-45849
was published
for
mindsdb
(pip)
Sep 12, 2024
MindsDB Eval Injection vulnerability
High
CVE-2024-45848
was published
for
mindsdb
(pip)
Sep 12, 2024
ProTip!
Advisories are also available from the
GraphQL API