GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,582
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
34,806 advisories
Filter by severity
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check
High
GHSA-mf7q-r4rv-jv94
was published
for
github.com/crossplane/crossplane-runtime/v2
(Go)
Aug 27, 2026
libreoffice-convert vulnerable to path traversal / arbitrary file write
Moderate
CVE-2026-54732
was published
for
libreoffice-convert
(npm)
Aug 27, 2026
silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template
High
CVE-2026-54718
was published
for
symbiote/silverstripe-advancedworkflow
(Composer)
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter
Low
CVE-2026-42350
was published
for
github.com/akuity/kargo
(Go)
Aug 27, 2026
n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)
Moderate
CVE-2026-54687
was published
for
n8n-nodes-sqlite3
(npm)
Aug 27, 2026
cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions
Low
CVE-2026-54713
was published
for
cakephp/queue
(Composer)
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
High
CVE-2026-54721
was published
for
silverstripe/userforms
(Composer)
Aug 27, 2026
Silverstripe Framework: Possible XSS attack through media embed
Moderate
CVE-2026-54720
was published
for
silverstripe/framework
(Composer)
Aug 27, 2026
OpenSTAManager has HTML Injection in modules/utenti/edit.php
Low
CVE-2026-44701
was published
for
devcode-it/openstamanager
(Composer)
Aug 26, 2026
LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates
High
GHSA-7w8c-qgxg-m7jx
was published
for
librenms/librenms
(Composer)
Aug 26, 2026
asyncssh has SCP Path Traversal to Arbitrary File Write
High
CVE-2026-54591
was published
for
asyncssh
(pip)
Aug 26, 2026
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
Moderate
CVE-2026-54590
was published
for
asyncssh
(pip)
Aug 26, 2026
cakephp/debug_kit: MailPreview contains unsafe reflection
Moderate
CVE-2026-54614
was published
for
cakephp/debug_kit
(Composer)
Aug 26, 2026
senaite.core Vulnerable to Eval Injection and Missing Authorization
Critical
CVE-2026-54569
was published
for
senaite.core
(pip)
Aug 26, 2026
SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed
High
CVE-2026-54606
was published
for
suneditor
(npm)
Aug 26, 2026
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
High
CVE-2026-54563
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Aug 26, 2026
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
Moderate
GHSA-x287-5c68-36wp
was published
for
openwisp-ipam
(pip)
Aug 26, 2026
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
Critical
GHSA-93qj-5q5v-3c2h
was published
for
pantheon-agents
(pip)
Aug 26, 2026
AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore
Moderate
CVE-2026-55688
was published
for
org.asynchttpclient:async-http-client
(Maven)
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
CVE-2026-54786
was published
for
wasmtime-wasi
(Rust)
Aug 26, 2026
@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys
High
CVE-2026-54511
was published
for
@logtape/syslog
(npm)
Aug 26, 2026
IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries
High
CVE-2026-54550
was published
for
org.codehaus.izpack:izpack-installer
(Maven)
Aug 26, 2026
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system
Critical
CVE-2026-54523
was published
for
github.com/kyverno/kyverno
(Go)
Aug 26, 2026
kas Persistently Disables SSH Host Key Checking
Low
CVE-2026-54548
was published
for
kas
(pip)
Aug 26, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
Moderate
CVE-2026-54553
was published
for
starlette-admin
(pip)
Aug 26, 2026
ProTip!
Advisories are also available from the
GraphQL API