GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
218 advisories
Filter by severity
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7...
High
Unreviewed
CVE-2026-18127
was published
Aug 11, 2026
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
High
GHSA-hmq2-w58f-27jc
was published
for
GitPython
(pip)
Aug 7, 2026
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability...
High
Unreviewed
CVE-2026-54200
was published
Aug 7, 2026
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion ...
High
Unreviewed
CVE-2026-12070
was published
Aug 7, 2026
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
GeoDjango spatial...
High
Unreviewed
CVE-2026-15307
was published
Aug 4, 2026
Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
High
GHSA-88pr-878c-24wf
was published
for
flowise
(npm)
Aug 4, 2026
External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies...
High
Unreviewed
CVE-2026-18806
was published
Aug 4, 2026
External control of file name or path in Microsoft Edge for Android allows an unauthorized...
High
Unreviewed
CVE-2026-65802
was published
Aug 4, 2026
External control of file name or path in Microsoft Edge for Android allows an unauthorized...
High
Unreviewed
CVE-2026-66310
was published
Aug 4, 2026
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
High
GHSA-3f7w-8rr8-f37f
was published
for
GitPython
(pip)
Aug 3, 2026
RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to...
High
Unreviewed
CVE-2026-64816
was published
Jul 31, 2026
Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly...
High
Unreviewed
CVE-2026-65896
was published
Jul 23, 2026
n8n: Edit Image Node Format Injection Allows Arbitrary File Write
High
GHSA-xmc9-4f2h-jf9c
was published
for
n8n
(npm)
Jul 22, 2026
The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions...
High
Unreviewed
CVE-2026-14551
was published
Jul 22, 2026
An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 ...
High
Unreviewed
CVE-2026-9587
was published
Jul 17, 2026
Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process...
High
Unreviewed
CVE-2026-61873
was published
Jul 15, 2026
Improper Restriction of Communication Channel to Intended Endpoints and External Control of File...
High
Unreviewed
CVE-2026-8920
was published
Jul 15, 2026
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode
High
CVE-2026-54629
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
yutu: Arbitrary File Write via MCP `caption-download` Tool
High
CVE-2026-50158
was published
for
github.com/eat-pray-ai/yutu
(Go)
Jul 14, 2026
External control of file name or path in Windows Ancillary Function Driver for WinSock allows an...
High
Unreviewed
CVE-2026-50462
was published
Jul 14, 2026
External control of file name or path in SQL Server allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-55002
was published
Jul 14, 2026
Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including...
High
Unreviewed
CVE-2026-15736
was published
Jul 14, 2026
OpenPLC Runtime v3 contains an authenticated arbitrary file write
vulnerability in the legacy...
High
Unreviewed
CVE-2026-14480
was published
Jul 11, 2026
mcp-atlassian: Arbitrary server-side file read via attachment upload
High
GHSA-wm45-qh3g-v83f
was published
for
mcp-atlassian
(pip)
Jul 10, 2026
In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS...
High
Unreviewed
CVE-2026-59793
was published
Jul 10, 2026
ProTip!
Advisories are also available from the
GraphQL API