GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,967
Maven
5,000+
npm
5,000+
NuGet
973
pip
5,000+
Pub
13
RubyGems
1,064
Rust
1,387
Swift
56
Unreviewed advisories
All unreviewed
5,000+
16 advisories
Filter by severity
Pimcore vulnerable to SQL injection via unsanitized filter value in Dependency Dao RLIKE clause
Moderate
CVE-2026-27461
was published
for
pimcore/pimcore
(Composer)
Feb 24, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
High
CVE-2026-3105
was published
for
mautic/core
(Composer)
Feb 25, 2026
@actual-app/sync-server: Missing authorization in sync endpoints allows cross-user budget file access in multi-user mode
Moderate
CVE-2026-27638
was published
for
@actual-app/sync-server
(npm)
Feb 27, 2026
BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction
High
CVE-2026-27905
was published
for
bentoml
(pip)
Mar 3, 2026
NocoDB Vulnerable to SQL Injection via DATEADD Formula
Moderate
CVE-2026-28399
was published
for
nocodb
(npm)
Mar 3, 2026
OpenClaw browser navigation guard allowed non-network URL schemes, enabling authenticated browser-tool users to access file:// local files
Moderate
CVE-2026-32008
was published
for
openclaw
(npm)
Mar 3, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
CVE-2026-29178
was published
for
lemmy_routes
(Rust)
Mar 4, 2026
AzuraCast: RCE via Liquidsoap string interpolation injection in station metadata and playlist URLs
High
GHSA-93fx-5qgc-wr38
was published
for
azuracast/azuracast
(Composer)
Mar 9, 2026
Craft CMS vulnerable to behavior injection RCE via EntryTypesController
High
CVE-2026-32263
was published
for
craftcms/cms
(Composer)
Mar 16, 2026
Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones API
High
CVE-2026-30932
was published
for
froxlor/froxlor
(Composer)
Mar 24, 2026
Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)
High
CVE-2026-27018
was published
for
github.com/gotenberg/gotenberg/v7
(Go)
Mar 30, 2026
Marimo: Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
Critical
CVE-2026-39987
was published
for
marimo
(pip)
Apr 8, 2026
ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView
Critical
CVE-2026-42601
was published
for
archivebox
(pip)
May 4, 2026
Dozzle's Cross-Site WebSocket Hijacking (CSWSH) on exec/attach endpointsbypasses authentication
High
CVE-2026-44985
was published
for
github.com/amir20/dozzle
(Go)
May 11, 2026
vm2 has a sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks
High
CVE-2026-47135
was published
for
vm2
(npm)
May 29, 2026
PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)
Critical
CVE-2026-47392
was published
for
PraisonAI
(pip)
May 29, 2026
ProTip!
Advisories are also available from the
GraphQL API