GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,683
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,532
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
102 advisories
Filter by severity
Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator
Critical
CVE-2026-71867
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli
Critical
CVE-2026-71865
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client
Critical
CVE-2026-71864
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client
Critical
CVE-2026-71866
was published
for
orval
(npm)
Sep 2, 2026
Faker: helpers.fake exploitable into arbritary code execution
High
CVE-2026-73231
was published
for
@faker-js/faker
(npm)
Sep 2, 2026
senaite.core Vulnerable to Eval Injection and Missing Authorization
Critical
CVE-2026-54569
was published
for
senaite.core
(pip)
Aug 26, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
Critical
CVE-2026-61539
was published
for
xinference
(pip)
Aug 21, 2026
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
Critical
CVE-2026-69264
was published
for
flowise
(npm)
Aug 4, 2026
AWS Amplify Studio UI Component Properties Has an Input Validation Issue
Critical
CVE-2025-4318
was published
for
@aws-amplify/codegen-ui-react
(npm)
Jul 30, 2026
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
High
CVE-2026-55415
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
High
CVE-2026-45293
was published
for
wp-coding-standards/wpcs
(Composer)
Jul 28, 2026
NLTK vulnerable to Eval Injection via collocations CLI arguments
High
CVE-2025-71408
was published
for
nltk
(pip)
Jul 25, 2026
django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization
High
GHSA-r3hx-x5rh-p9vv
was published
for
django-haystack
(pip)
Jul 15, 2026
MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php
High
CVE-2026-49273
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
Critical
CVE-2026-61667
was published
for
DIRAC
(pip)
Jul 13, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
Critical
CVE-2026-45579
was published
for
DIRAC
(pip)
Jul 13, 2026
EGroupware has Authenticated RCE via Malicious eTemplate Upload
High
CVE-2026-40187
was published
for
egroupware/egroupware
(Composer)
Jul 7, 2026
Rancher vulnerable to command injection through unsanitized YAML parameter
Critical
CVE-2026-44939
was published
for
github.com/rancher/rancher
(Go)
Jul 1, 2026
xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro
Critical
CVE-2026-44179
was published
for
com.xwiki.pro:xwiki-pro-macros
(Maven)
Jun 22, 2026
python-statemachine SCXML <data expr> Eval Injection
Critical
CVE-2026-47103
was published
for
python-statemachine
(pip)
Jun 18, 2026
Karate Mock Server RCE via embedded expression evaluation of request-derived data
High
GHSA-2c85-rfcc-g74j
was published
for
io.karatelabs:karate-core
(Maven)
Jun 18, 2026
Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
High
GHSA-cc5p-54x3-hcf8
was published
for
picklescan
(pip)
Jun 17, 2026
•
withdrawn
PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution
Critical
CVE-2026-47391
was published
for
PraisonAI
(pip)
May 29, 2026
Yamcs Vulnerable to Remote Code Execution via Mission Database algorithm override
Critical
CVE-2026-46562
was published
for
org.yamcs:yamcs-core
(Maven)
May 27, 2026
ProTip!
Advisories are also available from the
GraphQL API