GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
480 advisories
Filter by severity
Gitea: Local File Inclusion via file:// URI in Migration Restore
Moderate
CVE-2026-58420
was published
for
gitea.dev
(Go)
Jul 21, 2026
The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions...
High
Unreviewed
CVE-2026-14551
was published
Jul 22, 2026
n8n: Edit Image Node Format Injection Allows Arbitrary File Write
High
GHSA-xmc9-4f2h-jf9c
was published
for
n8n
(npm)
Jul 22, 2026
LiteLLM: Local file read via request-supplied OIDC file references
Low
CVE-2026-59819
was published
for
litellm
(pip)
Jul 22, 2026
Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly...
High
Unreviewed
CVE-2026-65896
was published
Jul 23, 2026
ImageMagick: Policy Bypass in concatenate operation due to missing checks
Moderate
CVE-2026-55628
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
Critical
GHSA-68r5-9hpg-7qw9
was published
for
org.openidentityplatform.opendj:opendj-dsml-servlet
(Maven)
Jul 24, 2026
proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An...
Moderate
Unreviewed
CVE-2026-57916
was published
Jul 27, 2026
GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and...
Moderate
Unreviewed
CVE-2026-56390
was published
Jul 29, 2026
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a...
Moderate
Unreviewed
CVE-2026-15382
was published
Jul 30, 2026
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
Critical
CVE-2026-67429
was published
for
flyto-core
(pip)
Jul 30, 2026
RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to...
High
Unreviewed
CVE-2026-64816
was published
Jul 31, 2026
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
High
GHSA-3f7w-8rr8-f37f
was published
for
GitPython
(pip)
Aug 3, 2026
GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
Moderate
GHSA-539m-9xh6-q6rr
was published
for
GitPython
(pip)
Aug 3, 2026
External control of file name or path in Microsoft Edge for Android allows an unauthorized...
High
Unreviewed
CVE-2026-65802
was published
Aug 4, 2026
External control of file name or path in Microsoft Edge for Android allows an unauthorized...
High
Unreviewed
CVE-2026-66310
was published
Aug 4, 2026
External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies...
High
Unreviewed
CVE-2026-18806
was published
Aug 4, 2026
Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
High
GHSA-88pr-878c-24wf
was published
for
flowise
(npm)
Aug 4, 2026
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
GeoDjango spatial...
High
Unreviewed
CVE-2026-15307
was published
Aug 4, 2026
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not...
Critical
Unreviewed
CVE-2026-16054
was published
Aug 6, 2026
A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function...
Moderate
Unreviewed
CVE-2026-19011
was published
Aug 6, 2026
A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of...
Moderate
Unreviewed
CVE-2026-19009
was published
Aug 6, 2026
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion ...
High
Unreviewed
CVE-2026-12070
was published
Aug 7, 2026
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability...
High
Unreviewed
CVE-2026-54200
was published
Aug 7, 2026
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
Moderate
GHSA-hh9p-6wh2-4mfc
was published
for
GitPython
(pip)
Aug 7, 2026
ProTip!
Advisories are also available from the
GraphQL API