GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,863
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,586
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
270 advisories
Filter by severity
vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts
High
CVE-2026-92950
was published
for
vm2
(npm)
Oct 1, 2026
vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
Critical
CVE-2026-92951
was published
for
vm2
(npm)
Oct 1, 2026
In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was...
High
Unreviewed
CVE-2026-100256
was published
Sep 30, 2026
When converting baserCMS4-style addons to baserCMS5-style ones,
BcAddonMigrator includes "config...
High
Unreviewed
CVE-2026-97150
was published
Sep 30, 2026
A flaw was found in kube-compare. When processing a 'container://' reference path, the tool...
High
Unreviewed
CVE-2026-87114
was published
Sep 28, 2026
Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to...
Moderate
Unreviewed
CVE-2026-96443
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to...
High
Unreviewed
CVE-2026-17647
was published
Sep 23, 2026
GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an...
High
Unreviewed
CVE-2026-96269
was published
Sep 22, 2026
Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree...
High
Unreviewed
CVE-2026-93993
was published
Sep 20, 2026
CM2507 IP cameras automatically execute a predetermined script from removable media without...
High
Unreviewed
CVE-2026-81305
was published
Sep 18, 2026
A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary...
Low
Unreviewed
CVE-2026-0303
was published
Sep 10, 2026
functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
High
CVE-2026-59176
was published
for
functype-mcp-server
(npm)
Sep 9, 2026
Joker linter executed project-local .jokerd/linter.* files during linting
High
CVE-2026-59172
was published
for
github.com/candid82/joker
(Go)
Sep 9, 2026
Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer,...
High
Unreviewed
CVE-2026-79721
was published
Sep 8, 2026
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a...
High
Unreviewed
CVE-2026-86504
was published
Sep 7, 2026
Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path...
High
Unreviewed
CVE-2026-86169
was published
Sep 5, 2026
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
High
CVE-2026-62680
was published
for
orval
(npm)
Sep 2, 2026
Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere...
High
Unreviewed
CVE-2026-58569
was published
Sep 1, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2...
High
Unreviewed
CVE-2026-18252
was published
Aug 26, 2026
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
High
CVE-2026-55522
was published
for
PraisonAI
(pip)
Aug 25, 2026
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
High
GHSA-ghvf-qf6h-g8x5
was published
for
@nocobase/server
(npm)
Aug 20, 2026
A flaw was found in acm-operator-bundle. The build process for this component downloads and runs...
High
Unreviewed
CVE-2026-76139
was published
Aug 19, 2026
A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a...
High
Unreviewed
CVE-2026-75569
was published
Aug 19, 2026
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
High
Unreviewed
CVE-2026-73367
was published
Aug 18, 2026
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit...
High
Unreviewed
CVE-2026-6464
was published
Aug 13, 2026
ProTip!
Advisories are also available from the
GraphQL API