GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
132,034 advisories
Filter by severity
node-tar: Negative tar entry size causes infinite loop in archive replace
High
CVE-2026-59874
was published
for
tar
(npm)
Jul 20, 2026
Socket.IO: Engine.IO Polling Transport Connection Exhaustion
High
CVE-2026-59725
was published
for
engine.io
(npm)
Jul 20, 2026
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
High
CVE-2026-13311
was published
for
shell-quote
(npm)
Jul 20, 2026
Directus: Authorization-dependent response served from unsegmented cache key
High
CVE-2026-61836
was published
for
directus
(npm)
Jul 20, 2026
Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
High
CVE-2026-61835
was published
for
directus
(npm)
Jul 20, 2026
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
High
CVE-2026-59922
was published
for
mistune
(pip)
Jul 20, 2026
Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
High
CVE-2026-44020
was published
for
docling
(pip)
Jun 3, 2026
Docling: Unsafe Zip Extraction in EasyOCR Model Download
High
CVE-2026-44017
was published
for
docling
(pip)
Jun 3, 2026
Docling: Unsafe Playwright-based HTML Rendering
High
CVE-2026-44016
was published
for
docling
(pip)
Jun 3, 2026
An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source...
High
Unreviewed
CVE-2026-52203
was published
Jul 17, 2026
Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to...
High
Unreviewed
CVE-2026-51833
was published
Jul 17, 2026
Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks.
The...
High
Unreviewed
CVE-2026-6656
was published
Jul 20, 2026
The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that...
High
Unreviewed
CVE-2026-60025
was published
Jul 17, 2026
An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory...
High
Unreviewed
CVE-2025-51678
was published
Jul 17, 2026
Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
High
CVE-2026-59925
was published
for
mistune
(pip)
Jul 20, 2026
Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler...
High
Unreviewed
CVE-2026-63770
was published
Jul 20, 2026
FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that...
High
Unreviewed
CVE-2026-64619
was published
Jul 20, 2026
VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability...
High
Unreviewed
CVE-2026-13381
was published
Jul 20, 2026
Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute...
High
Unreviewed
CVE-2026-63108
was published
Jul 20, 2026
Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java...
High
Unreviewed
CVE-2026-56623
was published
Jul 20, 2026
This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated attacker...
High
Unreviewed
CVE-2026-12341
was published
Jul 20, 2026
The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via...
High
Unreviewed
CVE-2026-60027
was published
Jul 20, 2026
The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution....
High
Unreviewed
CVE-2026-60026
was published
Jul 20, 2026
The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS...
High
Unreviewed
CVE-2026-60028
was published
Jul 20, 2026
DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow...
High
Unreviewed
CVE-2026-48389
was published
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API