GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
31,971 advisories
Filter by severity
An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly...
Critical
Unreviewed
CVE-2026-11386
was published
Jul 16, 2026
AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php...
Critical
Unreviewed
CVE-2026-63305
was published
Jul 16, 2026
stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in...
Critical
Unreviewed
CVE-2026-63306
was published
Jul 16, 2026
AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone...
Critical
Unreviewed
CVE-2026-63304
was published
Jul 16, 2026
An unauthenticated remote attacker can execute any command on the affected device due to not...
Critical
Unreviewed
CVE-2023-49899
was published
Jul 16, 2026
An unauthenticated remote attacker is able to perform remote code execution due to incorrectly...
Critical
Unreviewed
CVE-2023-49900
was published
Jul 16, 2026
Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization...
Critical
Unreviewed
CVE-2026-22752
was published
Jul 16, 2026
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 may...
Critical
Unreviewed
CVE-2026-15925
was published
Jul 16, 2026
The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one...
Critical
Unreviewed
CVE-2026-12492
was published
Jul 16, 2026
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass...
Critical
Unreviewed
CVE-2026-15013
was published
Jul 16, 2026
A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3...
Critical
Unreviewed
CVE-2026-26718
was published
Jul 16, 2026
xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server...
Critical
Unreviewed
CVE-2026-30618
was published
Jul 16, 2026
LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation...
Critical
Unreviewed
CVE-2026-30623
was published
Jul 16, 2026
An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a...
Critical
Unreviewed
CVE-2025-65720
was published
Jul 16, 2026
websocket-driver: Message corruption via abuse of protocol length headers
Critical
CVE-2026-54466
was published
for
websocket-driver
(npm)
Jul 15, 2026
Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause...
Critical
Unreviewed
CVE-2026-51380
was published
Jul 15, 2026
MantisBT: Reflected XSS in admin/install.php via unescaped printf
Critical
CVE-2026-52881
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\...
Critical
Unreviewed
CVE-2026-14960
was published
Jul 15, 2026
MantisBT: Reflected XSS in admin/install.php
Critical
CVE-2026-52847
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator
Critical
CVE-2026-47156
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex...
Critical
Unreviewed
CVE-2026-42533
was published
Jul 15, 2026
The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client...
Critical
Unreviewed
CVE-2026-61451
was published
Jul 15, 2026
Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing...
Critical
Unreviewed
CVE-2026-56699
was published
Jul 15, 2026
open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing...
Critical
Unreviewed
CVE-2026-56400
was published
Jul 15, 2026
An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain...
Critical
Unreviewed
CVE-2026-13385
was published
Jul 15, 2026
ProTip!
Advisories are also available from the
GraphQL API