GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
243 advisories
Filter by severity
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
Moderate
CVE-2026-62902
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-arm64
(NuGet)
Aug 11, 2026
when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase...
High
Unreviewed
CVE-2026-15560
was published
Aug 11, 2026
Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in...
Low
Unreviewed
CVE-2026-66843
was published
Aug 6, 2026
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
High
Unreviewed
CVE-2026-67623
was published
Aug 5, 2026
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
Moderate
GHSA-p5rm-jg5c-8c77
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
CVE-2026-59865
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
CVE-2026-59863
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
High
CVE-2026-59867
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
Critical
CVE-2026-59864
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe...
High
Unreviewed
CVE-2026-66141
was published
Jul 24, 2026
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python...
High
Unreviewed
CVE-2026-65908
was published
Jul 23, 2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied...
High
Unreviewed
CVE-2026-64807
was published
Jul 23, 2026
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project...
High
Unreviewed
CVE-2026-64809
was published
Jul 23, 2026
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project...
High
Unreviewed
CVE-2026-64808
was published
Jul 23, 2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project...
High
Unreviewed
CVE-2026-64806
was published
Jul 23, 2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project...
High
Unreviewed
CVE-2026-64804
was published
Jul 23, 2026
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting...
High
Unreviewed
CVE-2026-64811
was published
Jul 23, 2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project...
High
Unreviewed
CVE-2026-64805
was published
Jul 23, 2026
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the...
Low
Unreviewed
CVE-2026-16085
was published
Jul 18, 2026
ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes...
High
Unreviewed
CVE-2026-57860
was published
Jul 17, 2026
OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of...
High
Unreviewed
CVE-2026-62222
was published
Jul 17, 2026
Cherry Studio versions 1.2.2 through 1.9.12, fixed in commit 1518530, contain a remote code...
High
Unreviewed
CVE-2026-40501
was published
Jul 15, 2026
NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper...
Moderate
Unreviewed
CVE-2026-24226
was published
Jul 14, 2026
A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the...
Low
Unreviewed
CVE-2026-15519
was published
Jul 13, 2026
OpenClaw's marketplace runtime extension metadata could point at unscanned payloads
High
CVE-2026-53810
was published
for
openclaw
(npm)
Jul 2, 2026
ProTip!
Advisories are also available from the
GraphQL API