GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,683
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,532
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
5,687 advisories
Filter by severity
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
High
GHSA-vwf3-4xxj-qg6h
was published
for
mcp-contextforge-gateway
(pip)
Aug 25, 2026
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
High
CVE-2026-55585
was published
for
qwed
(pip)
Aug 25, 2026
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
Critical
CVE-2026-55546
was published
for
qwed-mcp
(pip)
Aug 25, 2026
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
High
CVE-2026-55522
was published
for
PraisonAI
(pip)
Aug 25, 2026
A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on...
Critical
Unreviewed
CVE-2026-57909
was published
Aug 25, 2026
SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1...
Critical
Unreviewed
CVE-2026-49845
was published
Aug 25, 2026
A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the...
Moderate
Unreviewed
CVE-2026-78654
was published
Aug 25, 2026
Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling...
High
Unreviewed
CVE-2026-56703
was published
Aug 25, 2026
An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute...
Critical
Unreviewed
CVE-2026-52490
was published
Aug 24, 2026
In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute...
High
Unreviewed
CVE-2025-26238
was published
Aug 24, 2026
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
Critical
CVE-2026-53710
was published
for
mcp-contextforge-gateway
(pip)
Aug 24, 2026
AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not...
High
Unreviewed
CVE-2026-76836
was published
Aug 24, 2026
A flaw was found in rpmbuild. When rpmbuild processes a crafted tarball in tarball mode, a...
High
Unreviewed
CVE-2026-78367
was published
Aug 24, 2026
Xinference loads models with Hugging Face remote code execution unconditionally enabled, and...
High
Unreviewed
CVE-2026-76841
was published
Aug 24, 2026
The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other...
High
Unreviewed
CVE-2026-19200
was published
Aug 24, 2026
A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive...
Moderate
Unreviewed
CVE-2026-78181
was published
Aug 24, 2026
A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the...
Moderate
Unreviewed
CVE-2026-78180
was published
Aug 24, 2026
A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability...
Moderate
Unreviewed
CVE-2026-78179
was published
Aug 24, 2026
A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite...
Moderate
Unreviewed
CVE-2026-78178
was published
Aug 24, 2026
Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7...
Critical
Unreviewed
CVE-2026-77992
was published
Aug 22, 2026
Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in...
Critical
Unreviewed
CVE-2026-76604
was published
Aug 22, 2026
Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
Critical
Unreviewed
CVE-2026-76605
was published
Aug 22, 2026
The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2026-3424
was published
Aug 22, 2026
The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting...
High
Unreviewed
CVE-2026-19221
was published
Aug 22, 2026
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
Critical
CVE-2026-77415
was published
for
jsonata
(npm)
Aug 21, 2026
ProTip!
Advisories are also available from the
GraphQL API