GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,683
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,532
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
5,687 advisories
Filter by severity
BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once...
High
Unreviewed
CVE-2026-82278
was published
Aug 28, 2026
Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that...
High
Unreviewed
CVE-2026-77939
was published
Aug 28, 2026
Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name
Critical
CVE-2026-55634
was published
for
pimcore/pimcore
(Composer)
Aug 28, 2026
CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on...
High
Unreviewed
CVE-2026-76148
was published
Aug 28, 2026
Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)
Critical
CVE-2026-55565
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
Critical
CVE-2026-55559
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`
Critical
CVE-2026-55511
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
High
CVE-2026-54757
was published
for
compliance-trestle
(pip)
Aug 28, 2026
Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling...
Critical
Unreviewed
CVE-2026-82244
was published
Aug 28, 2026
ServiceNow has remediated a sandbox escape security issue that was identified in the Now Platform...
High
Unreviewed
CVE-2026-6876
was published
Aug 27, 2026
Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection....
Critical
Unreviewed
CVE-2026-37003
was published
Aug 27, 2026
ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI...
Critical
Unreviewed
CVE-2026-18885
was published
Aug 27, 2026
openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls:...
Critical
Unreviewed
CVE-2026-81719
was published
Aug 27, 2026
ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that...
Critical
Unreviewed
CVE-2026-81096
was published
Aug 27, 2026
An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the...
Critical
Unreviewed
CVE-2026-75357
was published
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
High
CVE-2026-54721
was published
for
silverstripe/userforms
(Composer)
Aug 27, 2026
The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network...
High
Unreviewed
CVE-2026-19223
was published
Aug 27, 2026
The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to...
Moderate
Unreviewed
CVE-2026-19225
was published
Aug 27, 2026
In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering...
Critical
Unreviewed
CVE-2026-75414
was published
Aug 26, 2026
JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow...
Critical
Unreviewed
CVE-2026-75411
was published
Aug 26, 2026
A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component...
Critical
Unreviewed
CVE-2026-52103
was published
Aug 26, 2026
whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands...
High
Unreviewed
CVE-2026-58474
was published
Aug 26, 2026
The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against...
High
Unreviewed
CVE-2026-74851
was published
Aug 26, 2026
Code injection in Bisection in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to...
Moderate
Unreviewed
CVE-2026-79249
was published
Aug 25, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local...
High
Unreviewed
CVE-2026-65082
was published
Aug 25, 2026
ProTip!
Advisories are also available from the
GraphQL API