GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
132,034 advisories
Filter by severity
lodash vulnerable to Code Injection via `_.template` imports key names
High
CVE-2026-4800
was published
for
lodash
(npm)
Apr 1, 2026
listmonk's active sessions remain valid after password reset and password change
High
CVE-2026-34828
was published
for
github.com/knadh/listmonk
(Go)
Apr 1, 2026
NocoBase Has SQL Injection via template variable substitution in workflow SQL node
High
CVE-2026-34825
was published
for
@nocobase/plugin-workflow-sql
(npm)
Apr 1, 2026
ONNX: TOCTOU arbitrary file read/write in save_external_dat
High
GHSA-q56x-g2fj-4rj6
was published
for
onnx
(pip)
Apr 1, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
High
CVE-2026-34783
was published
for
github.com/MontFerret/ferret
(Go)
Apr 1, 2026
PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL
High
CVE-2026-34954
was published
for
praisonaiagents
(pip)
Apr 1, 2026
PraisonAI Has Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandbox
High
CVE-2026-34955
was published
for
praisonai
(pip)
Apr 1, 2026
KubeAI: OS Command Injection via Model URL in Ollama Engine startup probe allows arbitrary command execution in model pods
High
CVE-2026-34940
was published
for
github.com/kubeai-project/kubeai
(Go)
Apr 1, 2026
PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback
High
CVE-2026-34936
was published
for
praisonai
(pip)
Apr 1, 2026
PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution
High
CVE-2026-34937
was published
for
praisonaiagents
(pip)
Apr 1, 2026
Parser Server's streaming file download bypasses afterFind file trigger authorization
High
CVE-2026-34784
was published
for
parse-server
(npm)
Apr 1, 2026
Haraka affected by DoS via `__proto__` email header
High
CVE-2026-34752
was published
for
Haraka
(npm)
Apr 1, 2026
phpMyFAQ: Path Traversal - Arbitrary File Deletion in MediaBrowserController
High
CVE-2026-34728
was published
for
phpmyfaq/phpmyfaq
(Composer)
Apr 1, 2026
dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration
High
CVE-2026-34725
was published
for
dbgate-web
(npm)
Apr 1, 2026
Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write
High
CVE-2026-34591
was published
for
poetry
(pip)
Apr 1, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
High
CVE-2026-34572
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 1, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
High
CVE-2026-34570
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 1, 2026
SillyTavern: Path Traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user data root
High
CVE-2026-34524
was published
for
sillytavern
(npm)
Apr 1, 2026
SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory
High
CVE-2026-34522
was published
for
sillytavern
(npm)
Apr 1, 2026
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container...
High
Unreviewed
CVE-2026-4101
was published
Apr 1, 2026
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container...
High
Unreviewed
CVE-2026-1345
was published
Apr 1, 2026
ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the...
High
Unreviewed
CVE-2026-35000
was published
Apr 1, 2026
Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number...
High
Unreviewed
CVE-2026-25835
was published
Apr 1, 2026
Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6...
High
Unreviewed
CVE-2026-25833
was published
Apr 1, 2026
An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer...
High
Unreviewed
CVE-2026-34874
was published
Apr 1, 2026
ProTip!
Advisories are also available from the
GraphQL API