GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
5,666 advisories
Filter by severity
Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited...
High
Unreviewed
CVE-2026-58572
was published
Sep 1, 2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical...
Critical
Unreviewed
CVE-2026-18808
was published
Sep 1, 2026
A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows...
Critical
Unreviewed
CVE-2026-4813
was published
Sep 1, 2026
Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox,...
Low
Unreviewed
CVE-2026-80201
was published
Aug 31, 2026
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due...
Critical
Unreviewed
CVE-2026-19286
was published
Aug 29, 2026
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute...
High
Unreviewed
CVE-2026-18729
was published
Aug 29, 2026
BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once...
High
Unreviewed
CVE-2026-82278
was published
Aug 28, 2026
Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that...
High
Unreviewed
CVE-2026-77939
was published
Aug 28, 2026
Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name
Critical
CVE-2026-55634
was published
for
pimcore/pimcore
(Composer)
Aug 28, 2026
CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on...
High
Unreviewed
CVE-2026-76148
was published
Aug 28, 2026
Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)
Critical
CVE-2026-55565
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
Critical
CVE-2026-55559
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`
Critical
CVE-2026-55511
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
High
CVE-2026-54757
was published
for
compliance-trestle
(pip)
Aug 28, 2026
Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling...
Critical
Unreviewed
CVE-2026-82244
was published
Aug 28, 2026
ServiceNow has remediated a sandbox escape security issue that was identified in the Now Platform...
High
Unreviewed
CVE-2026-6876
was published
Aug 27, 2026
Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection....
Critical
Unreviewed
CVE-2026-37003
was published
Aug 27, 2026
ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI...
Critical
Unreviewed
CVE-2026-18885
was published
Aug 27, 2026
openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls:...
Critical
Unreviewed
CVE-2026-81719
was published
Aug 27, 2026
ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that...
Critical
Unreviewed
CVE-2026-81096
was published
Aug 27, 2026
An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the...
Critical
Unreviewed
CVE-2026-75357
was published
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
High
CVE-2026-54721
was published
for
silverstripe/userforms
(Composer)
Aug 27, 2026
The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network...
High
Unreviewed
CVE-2026-19223
was published
Aug 27, 2026
The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to...
Moderate
Unreviewed
CVE-2026-19225
was published
Aug 27, 2026
JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow...
Critical
Unreviewed
CVE-2026-75411
was published
Aug 26, 2026
ProTip!
Advisories are also available from the
GraphQL API