GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,821
Maven
5,000+
npm
5,000+
NuGet
939
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
30,224 advisories
Filter by severity
DeepSeek TUI: run_tests Tool Enables RCE via Malicious Repository Without Approval
Critical
CVE-2026-45311
was published
for
deepseek-tui
(npm)
May 14, 2026
Electerm: Importing unsafe bookmark data could lead to unsafe operation when clicking local type bookmark
Critical
CVE-2026-45058
was published
for
electerm
(npm)
May 14, 2026
Web::Passwd versions through 0.03 for Perl is vulnerable to RCE.
Web::Passwd is a small CGI...
Critical
Unreviewed
CVE-2026-8500
was published
May 14, 2026
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin...
Critical
Unreviewed
CVE-2025-27851
was published
May 13, 2026
Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an...
Critical
Unreviewed
CVE-2026-41615
was published
May 14, 2026
May 2026: This security advisory provides the details and fix information for a vulnerability...
Critical
Unreviewed
CVE-2026-20182
was published
May 14, 2026
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
Critical
CVE-2026-44990
was published
for
sanitize-html
(npm)
May 14, 2026
Portainer has an endpoint security bypass via Swarm service create/update
Critical
CVE-2026-44849
was published
for
github.com/portainer/portainer
(Go)
May 14, 2026
Portainer missing authorization on Docker plugin endpoints, which allows host RCE
Critical
CVE-2026-44848
was published
for
github.com/portainer/portainer
(Go)
May 14, 2026
n8n Has an XML Node Prototype Pollution Patch Bypass
Critical
CVE-2026-44791
was published
for
n8n
(npm)
May 14, 2026
n8n Has an Arbitrary File Read via Git Node
Critical
CVE-2026-44790
was published
for
n8n
(npm)
May 14, 2026
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
Critical
CVE-2026-44789
was published
for
n8n
(npm)
May 14, 2026
Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading
Critical
CVE-2026-8178
was published
for
com.amazon.redshift:redshift-jdbc42
(Maven)
May 14, 2026
Improper neutralization of special elements used in an SQL command ('SQL injection')...
Critical
Unreviewed
CVE-2025-11024
was published
May 14, 2026
Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software...
Critical
Unreviewed
CVE-2026-2347
was published
May 14, 2026
The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up...
Critical
Unreviewed
CVE-2026-6271
was published
May 14, 2026
The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing...
Critical
Unreviewed
CVE-2026-6510
was published
May 14, 2026
The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up...
Critical
Unreviewed
CVE-2026-6512
was published
May 14, 2026
The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin...
Critical
Unreviewed
CVE-2026-8181
was published
May 14, 2026
The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a...
Critical
Unreviewed
CVE-2026-31226
was published
May 12, 2026
The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion...
Critical
Unreviewed
CVE-2026-31216
was published
May 12, 2026
The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion...
Critical
Unreviewed
CVE-2026-31215
was published
May 12, 2026
The _load_model() function in the neural_magic_training.py script of the optimate project in...
Critical
Unreviewed
CVE-2026-31217
was published
May 12, 2026
The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution...
Critical
Unreviewed
CVE-2026-31228
was published
May 12, 2026
Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows...
Critical
Unreviewed
CVE-2020-37168
was published
May 13, 2026
ProTip!
Advisories are also available from the
GraphQL API