GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,865
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,587
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
5,642 advisories
Filter by severity
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to...
High
Unreviewed
CVE-2026-16468
was published
Sep 23, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to...
High
Unreviewed
CVE-2026-16672
was published
Sep 23, 2026
Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated...
High
Unreviewed
CVE-2026-76714
was published
Sep 22, 2026
Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass
Moderate
CVE-2026-76802
was published
for
github.com/projectdiscovery/nuclei/v3
(Go)
Sep 22, 2026
KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API
High
CVE-2026-62371
was published
for
github.com/kubeedge/kubeedge
(Go)
Sep 22, 2026
KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes
High
CVE-2026-62182
was published
for
github.com/kubeedge/kubeedge
(Go)
Sep 22, 2026
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection...
Critical
Unreviewed
CVE-2026-43641
was published
Sep 22, 2026
Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all...
Critical
Unreviewed
CVE-2026-80152
was published
Sep 22, 2026
Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all...
Critical
Unreviewed
CVE-2026-80151
was published
Sep 22, 2026
Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all...
Critical
Unreviewed
CVE-2026-80145
was published
Sep 22, 2026
Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all...
Critical
Unreviewed
CVE-2026-80144
was published
Sep 22, 2026
Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all...
Critical
Unreviewed
CVE-2026-80143
was published
Sep 22, 2026
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause...
High
Unreviewed
CVE-2026-65130
was published
Sep 22, 2026
D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code...
Critical
Unreviewed
CVE-2026-95675
was published
Sep 22, 2026
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote...
Critical
Unreviewed
CVE-2026-74849
was published
Sep 22, 2026
An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the...
High
Unreviewed
CVE-2026-79079
was published
Sep 22, 2026
Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command...
Critical
Unreviewed
CVE-2026-93012
was published
Sep 21, 2026
An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5...
High
Unreviewed
CVE-2026-84285
was published
Sep 21, 2026
Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that...
High
Unreviewed
CVE-2026-89139
was published
Sep 21, 2026
getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that...
High
Unreviewed
CVE-2026-94106
was published
Sep 20, 2026
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands...
High
Unreviewed
CVE-2026-84085
was published
Sep 18, 2026
IBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands...
Moderate
Unreviewed
CVE-2026-81623
was published
Sep 18, 2026
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute...
High
Unreviewed
CVE-2026-82887
was published
Sep 18, 2026
IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection...
Critical
Unreviewed
CVE-2026-80442
was published
Sep 18, 2026
IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the...
High
Unreviewed
CVE-2026-81669
was published
Sep 18, 2026
ProTip!
Advisories are also available from the
GraphQL API