GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,865
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,587
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
5,642 advisories
Filter by severity
Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system...
High
Unreviewed
CVE-2026-85082
was published
Sep 25, 2026
The affected products are vulnerable to command injection attack that could allow an...
Critical
Unreviewed
CVE-2026-93289
was published
Sep 24, 2026
An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web...
Critical
Unreviewed
CVE-2026-13249
was published
Sep 24, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to...
High
Unreviewed
CVE-2026-81545
was published
Sep 24, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to...
High
Unreviewed
CVE-2026-81539
was published
Sep 24, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to...
High
Unreviewed
CVE-2026-81548
was published
Sep 24, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to...
High
Unreviewed
CVE-2026-81552
was published
Sep 24, 2026
A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or...
High
Unreviewed
CVE-2026-95521
was published
Sep 24, 2026
A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a...
High
Unreviewed
CVE-2026-95519
was published
Sep 24, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to...
High
Unreviewed
CVE-2026-81537
was published
Sep 24, 2026
Insufficient input sanitization of shell metacharacters in the Brocade SANnav CLI scripting...
High
Unreviewed
CVE-2026-82369
was published
Sep 23, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to...
High
Unreviewed
CVE-2026-80425
was published
Sep 23, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to...
High
Unreviewed
CVE-2026-80412
was published
Sep 23, 2026
IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially...
Critical
Unreviewed
CVE-2026-6721
was published
Sep 23, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to...
High
Unreviewed
CVE-2026-80379
was published
Sep 23, 2026
OS command injection in Plesk allows remote authenticated users to execute arbitrary code with...
Critical
Unreviewed
CVE-2026-87898
was published
Sep 23, 2026
OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting
High
CVE-2026-77601
was published
for
openc3
(RubyGems)
Sep 23, 2026
Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore...
High
Unreviewed
CVE-2026-93349
was published
Sep 23, 2026
ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code...
Critical
Unreviewed
CVE-2026-19599
was published
Sep 23, 2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable...
High
Unreviewed
CVE-2026-76978
was published
Sep 23, 2026
CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated...
High
Unreviewed
CVE-2026-15027
was published
Sep 23, 2026
An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket...
Moderate
Unreviewed
CVE-2026-50227
was published
Sep 23, 2026
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection...
High
Unreviewed
CVE-2026-94367
was published
Sep 23, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to...
High
Unreviewed
CVE-2026-17102
was published
Sep 23, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 px-runtime could allow a remote authenticated...
High
Unreviewed
CVE-2026-16469
was published
Sep 23, 2026
ProTip!
Advisories are also available from the
GraphQL API