GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,606
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,831
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
15 advisories
Filter by severity
RCE in Mingsoft MCMS
Critical
CVE-2022-22930
was published
for
net.mingsoft:ms-mcms
(Maven)
Jan 22, 2022
Code injection in RazorEngine
Critical
CVE-2021-46703
was published
for
RazorEngine
(NuGet)
Mar 7, 2022
Shopware Remote Code Execution Vulnerability
Critical
GHSA-83jv-4prm-34g7
was published
for
shopware/shopware
(Composer)
May 21, 2024
changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution
Critical
CVE-2024-32651
was published
for
changedetection.io
(pip)
Oct 15, 2024
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user
Critical
CVE-2025-49136
was published
for
github.com/knadh/listmonk
(Go)
Jun 9, 2025
LaRecipe is vulnerable to Server-Side Template Injection attacks
Critical
CVE-2025-53833
was published
for
binarytorch/larecipe
(Composer)
Jul 14, 2025
jinjava has Sandbox Bypass via JavaType-Based Deserialization
Critical
CVE-2025-59340
was published
for
com.hubspot.jinjava:jinjava
(Maven)
Sep 17, 2025
XDocReport affected by a Server-Side Template Injection (SSTI) vulnerability
Critical
CVE-2025-64087
was published
for
fr.opensagres.xdocreport:fr.opensagres.xdocreport.template.freemarker
(Maven)
Jan 20, 2026
JinJava Bypass through ForTag leads to Arbitrary Java Execution
Critical
CVE-2026-25526
was published
for
com.hubspot.jinjava:jinjava
(Maven)
Feb 3, 2026
Flask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template Injection
Critical
CVE-2026-27641
was published
for
flask-reuploaded
(pip)
Feb 25, 2026
Craft CMS Vulnerable to Authenticated RCE via "craft.app.fs.write()" in Twig Templates
Critical
CVE-2026-28697
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Incus vulnerable to arbitrary file read and write through pongo templates
Critical
CVE-2026-33897
was published
for
github.com/lxc/incus
(Go)
Mar 27, 2026
Zebra node crash — V5 transaction hash panic (P2P reachable)
Critical
CVE-2026-34202
was published
for
zebra-chain
(Rust)
Mar 27, 2026
Improper restriction of the scope of accessible objects in Thymeleaf expressions
Critical
CVE-2026-40477
was published
for
org.thymeleaf:thymeleaf
(Maven)
Apr 15, 2026
Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
Critical
CVE-2026-40478
was published
for
org.thymeleaf:thymeleaf
(Maven)
Apr 15, 2026
ProTip!
Advisories are also available from the
GraphQL API