GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
64 advisories
Filter by severity
DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field...
Critical
Unreviewed
CVE-2026-72742
was published
Aug 11, 2026
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not...
Critical
Unreviewed
CVE-2026-16054
was published
Aug 6, 2026
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
Critical
CVE-2026-67429
was published
for
flyto-core
(pip)
Jul 30, 2026
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
Critical
GHSA-68r5-9hpg-7qw9
was published
for
org.openidentityplatform.opendj:opendj-dsml-servlet
(Maven)
Jul 24, 2026
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode
Critical
CVE-2026-50006
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that...
Critical
Unreviewed
CVE-2026-61462
was published
Jul 13, 2026
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file().
send_file...
Critical
Unreviewed
CVE-2026-8450
was published
May 27, 2026
Mautic vulnerable to Path Traversal via Campaign Import
Critical
CVE-2026-9559
was published
for
mautic/core
(Composer)
Jul 2, 2026
Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api...
Critical
Unreviewed
CVE-2025-71333
was published
Jun 26, 2026
The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File...
Critical
Unreviewed
CVE-2026-6070
was published
Jul 1, 2026
Incus has an arbitrary file write via path traversal in S3 multipart upload
Critical
CVE-2026-48753
was published
for
github.com/lxc/incus/v7/cmd/incusd
(Go)
Jun 26, 2026
Incus has arbitrary file read+write on host via templates/ symlink in malicious image
Critical
CVE-2026-48752
was published
for
github.com/lxc/incus/v7/cmd/incusd
(Go)
Jun 26, 2026
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image
Critical
CVE-2026-48750
was published
for
github.com/lxc/incus/v7/cmd/incusd
(Go)
Jun 26, 2026
Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image
Critical
CVE-2026-48749
was published
for
github.com/lxc/incus/v7/cmd/incusd
(Go)
Jun 26, 2026
Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access...
Critical
Unreviewed
CVE-2025-71334
was published
Jun 26, 2026
Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process...
Critical
Unreviewed
CVE-2025-71338
was published
Jun 26, 2026
GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open()...
Critical
Unreviewed
CVE-2026-11526
was published
Jun 14, 2026
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to...
Critical
Unreviewed
CVE-2026-47643
was published
Jun 9, 2026
An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the...
Critical
Unreviewed
CVE-2026-39006
was published
Jun 15, 2026
Langflow has an Arbitrary File Write (RCE) via v2 API
Critical
CVE-2026-33309
was published
for
langflow
(pip)
Mar 19, 2026
External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource...
Critical
Unreviewed
CVE-2024-9142
was published
Sep 25, 2024
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the...
Critical
Unreviewed
CVE-2026-47357
was published
May 19, 2026
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL...
Critical
Unreviewed
CVE-2026-47358
was published
May 19, 2026
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6...
Critical
Unreviewed
CVE-2026-30903
was published
Mar 11, 2026
External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote...
Critical
Unreviewed
CVE-2026-8043
was published
May 12, 2026
ProTip!
Advisories are also available from the
GraphQL API