GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,538
Maven
5,000+
npm
5,000+
NuGet
914
pip
4,790
Pub
13
RubyGems
1,037
Rust
1,232
Swift
53
Unreviewed advisories
All unreviewed
5,000+
48 advisories
Filter by severity
Agno is vulnerable to Eval Injection
Critical
CVE-2026-35002
was published
for
agno
(pip)
Apr 2, 2026
Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
Critical
CVE-2026-33017
was published
for
langflow
(pip)
Mar 17, 2026
OpenStack Vitrage: Unauthorized Access to the Host can Lead to Eval Injection
Critical
CVE-2026-28370
was published
for
vitrage
(pip)
Feb 27, 2026
n8n has Unauthenticated Expression Evaluation via Form Node
Critical
CVE-2026-27493
was published
for
n8n
(npm)
Feb 25, 2026
Budibase: Remote Code Execution via Unsafe eval() in View Filter Map Function (Budibase Cloud)
Critical
CVE-2026-27702
was published
for
budibase
(npm)
Feb 25, 2026
n8n Unsafe Workflow Expression Evaluation Allows Remote Code Execution
Critical
CVE-2026-1470
was published
for
n8n
(npm)
Jan 27, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
Critical
CVE-2025-68271
was published
for
openc3
(RubyGems)
Jan 13, 2026
Flowise vulnerable to RCE via Dynamic function constructor injection
Critical
CVE-2025-55346
was published
for
flowise
(npm)
Oct 6, 2025
com.xwiki.confluencepro:application-confluence-migrator-pro-ui Remote Code Execution via unescaped translations
Critical
CVE-2025-27603
was published
for
com.xwiki.confluencepro:application-confluence-migrator-pro-ui
(Maven)
Mar 7, 2025
XWiki Platform allows remote code execution as guest via SolrSearchMacros request
Critical
CVE-2025-24893
was published
for
org.xwiki.platform:xwiki-platform-search-solr-ui
(Maven)
Feb 20, 2025
DocsGPT Allows Remote Code Execution
Critical
CVE-2025-0868
was published
for
docsgpt
(npm)
Feb 20, 2025
GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressions
Critical
CVE-2024-36404
was published
for
org.geotools.xsd:gt-xsd-core
(Maven)
Feb 5, 2025
LangChain Experimental Eval Injection vulnerability
Critical
CVE-2024-46946
was published
for
langchain-experimental
(pip)
Sep 19, 2024
Chaosblade vulnerable to OS command execution
Critical
CVE-2023-47105
was published
for
github.com/chaosblade-io/chaosblade
(Go)
Sep 18, 2024
XWiki Platform vulnerable to remote code execution from account via SearchSuggestConfigSheet
Critical
CVE-2024-37901
was published
for
org.xwiki.platform:xwiki-platform-search-ui
(Maven)
Jul 31, 2024
Remote Code Execution (RCE) vulnerability in geoserver
Critical
CVE-2024-36401
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jul 1, 2024
XWiki Commons missing escaping of `{` in Velocity escapetool allows remote code execution
Critical
CVE-2024-31996
was published
for
org.xwiki.commons:xwiki-commons-velocity
(Maven)
Apr 10, 2024
XWiki Platform CSRF remote code execution through scheduler job's document reference
Critical
CVE-2024-31986
was published
for
org.xwiki.platform:xwiki-platform-scheduler-ui
(Maven)
Apr 10, 2024
XWiki Platform: Remote code execution through space title and Solr space facet
Critical
CVE-2024-31984
was published
for
org.xwiki.platform:xwiki-platform-search-solr-ui
(Maven)
Apr 10, 2024
XWiki Platform: Remote code execution as guest via DatabaseSearch
Critical
CVE-2024-31982
was published
for
org.xwiki.platform:xwiki-platform-search-ui
(Maven)
Apr 10, 2024
XWiki Platform: Remote code execution from account via SearchSuggestSourceSheet
Critical
CVE-2024-31465
was published
for
org.xwiki.platform:xwiki-platform-search-ui
(Maven)
Apr 10, 2024
Arbitrary Code Execution in Pillow
Critical
CVE-2023-50447
was published
for
Pillow
(pip)
Jan 19, 2024
XWiki Remote Code Execution Vulnerability via User Registration
Critical
CVE-2024-21650
was published
for
org.xwiki.platform:xwiki-platform-administration-ui
(Maven)
Jan 8, 2024
Remote code execution/programming rights with configuration section from any user account
Critical
CVE-2023-50723
was published
for
org.xwiki.platform:xwiki-platform-administration-ui
(Maven)
Dec 16, 2023
XWiki Platform vulnerable to remote code execution through the section parameter in Administration as guest
Critical
CVE-2023-46731
was published
for
org.xwiki.platform:xwiki-platform-administration
(Maven)
Nov 8, 2023
ProTip!
Advisories are also available from the
GraphQL API