GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,821
Maven
5,000+
npm
5,000+
NuGet
939
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
30,224 advisories
Filter by severity
SandboxJS has a sandbox escape via Function.caller leakage of internal call op
Critical
CVE-2026-43898
was published
for
@nyariv/sandboxjs
(npm)
May 11, 2026
S3-Proxy has Security Issues in its Resource Path Matching Implementation
Critical
CVE-2026-42882
was published
for
github.com/oxyno-zeta/s3-proxy
(Go)
May 5, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
Critical
CVE-2026-42864
was published
for
firefighter-incident
(pip)
May 5, 2026
Angular Expressions - Remote Code Execution using filters
Critical
CVE-2026-44643
was published
for
angular-expressions
(npm)
May 11, 2026
Grav Vulnerable to Privilege Escalation via Missing Server-Side Validation of groups/access
Critical
CVE-2026-42613
was published
for
getgrav/grav
(Composer)
May 5, 2026
Grav Vulnerable to Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install Feature
Critical
CVE-2026-42607
was published
for
getgrav/grav
(Composer)
May 5, 2026
Spring AI: SpEL injection is triggered when a user-supplied value is used as a filter expression key
Critical
CVE-2026-22738
was published
for
org.springframework.ai:spring-ai-vector-store
(Maven)
Mar 27, 2026
Pelican Web UI Affected by a Privilege Escalation Attack
Critical
CVE-2026-42571
was published
for
github.com/pelicanplatform/pelican
(Go)
May 4, 2026
phpVMS has an /importer authorization bypass causing full database wipe
Critical
CVE-2026-42569
was published
for
nabeel/phpvms
(Composer)
May 4, 2026
auth: Patreon provider assigns the same local user ID to every authenticated Patreon account, enabling cross‑user impersonation
Critical
CVE-2026-42560
was published
for
github.com/go-pkgz/auth
(Go)
Apr 30, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
Critical
CVE-2026-42354
was published
for
sentry
(pip)
Apr 30, 2026
TorrentPier Deserialization of Untrusted Data vulnerability
Critical
CVE-2024-40624
was published
for
torrentpier/torrentpier
(Composer)
Jul 15, 2024
Electerm users can run dangrous code through link or command line
Critical
CVE-2026-43944
was published
for
electerm
(npm)
May 8, 2026
NornicDB has Improper Network Binding in its Bolt Server, allowing unauthorized remote access
Critical
CVE-2026-42072
was published
for
github.com/orneryd/nornicdb
(Go)
Apr 22, 2026
openvpn-auth-oauth2 returns FUNC_SUCCESS on client-deny, allowing unauthenticated VPN access
Critical
CVE-2026-41070
was published
for
github.com/jkroepke/openvpn-auth-oauth2
(Go)
Apr 22, 2026
Zebra has Consensus Divergence in Transparent Sighash Hash-Type Handling due to Stale Buffer
Critical
CVE-2026-44497
was published
for
zebra-script
(Rust)
May 7, 2026
Zebra's Block Validator Undercounts Coinbase and P2SH Sigops
Critical
CVE-2026-44498
was published
for
zebrad
(Rust)
May 7, 2026
Mapfish Print: Remote Code Injection (RCE) in Dynamic table
Critical
CVE-2026-44672
was published
for
org.mapfish.print:print-lib
(Maven)
May 13, 2026
Insufficient ownership checks in `clientarea.php` allow an authenticated client area user to...
Critical
Unreviewed
CVE-2026-29204
was published
May 12, 2026
SillyTavern has a Path Traversal issue
Critical
CVE-2026-44650
was published
for
sillytavern
(npm)
May 12, 2026
SillyTavern has Authentication Bypass via SSO Header Injection
Critical
CVE-2026-44649
was published
for
sillytavern
(npm)
May 12, 2026
esm.sh: Legacy Route Path Traversal Can Lead to RCE
Critical
CVE-2026-44593
was published
for
github.com/esm-dev/esm.sh
(Go)
May 12, 2026
SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space...
Critical
Unreviewed
CVE-2026-8430
was published
May 12, 2026
Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of...
Critical
Unreviewed
CVE-2026-34659
was published
May 12, 2026
Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect...
Critical
Unreviewed
CVE-2026-34660
was published
May 12, 2026
ProTip!
Advisories are also available from the
GraphQL API