GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,683
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,532
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
5,687 advisories
Filter by severity
An insufficiently validated configuration field in Kibana's Cribl integration allows an...
Moderate
Unreviewed
CVE-2026-78593
was published
Sep 3, 2026
Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)
Critical
CVE-2026-62681
was published
for
orval
(npm)
Sep 3, 2026
Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)
Critical
CVE-2026-62682
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via schema default -> zod module-level template literal
Critical
CVE-2026-72717
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via array-items default -> zod module-level template literal
Critical
CVE-2026-71869
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via header-parameter default -> zod module-level template literal
Critical
CVE-2026-71871
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via enum-typed default -> zod module-level template literal
Critical
CVE-2026-71868
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli
Critical
CVE-2026-71865
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client
Critical
CVE-2026-71864
was published
for
orval
(npm)
Sep 3, 2026
n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the ...
High
Unreviewed
CVE-2026-85169
was published
Sep 3, 2026
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
Critical
CVE-2026-62674
was published
for
omnigent
(pip)
Sep 2, 2026
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
High
CVE-2026-62675
was published
for
omnigent
(pip)
Sep 2, 2026
A flaw was found in submariner. In cert-auth mode, the connection configuration is built using...
Critical
Unreviewed
CVE-2026-66786
was published
Sep 2, 2026
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their...
High
Unreviewed
CVE-2026-84645
was published
Sep 2, 2026
The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging...
Critical
Unreviewed
CVE-2026-77009
was published
Sep 2, 2026
Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()
High
CVE-2026-64850
was published
for
getgrav/grav
(Composer)
Sep 2, 2026
pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install
High
CVE-2026-82393
was published
for
pnpm
(npm)
Sep 2, 2026
An unauthenticated remote code execution vulnerability exists in the underlying operating system...
Critical
Unreviewed
CVE-2026-73701
was published
Sep 1, 2026
An eval() injection vulnerability in the get_list function in modules/meta_parser.py in...
High
Unreviewed
CVE-2026-51974
was published
Sep 1, 2026
Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited...
High
Unreviewed
CVE-2026-58572
was published
Sep 1, 2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical...
Critical
Unreviewed
CVE-2026-18808
was published
Sep 1, 2026
A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows...
Critical
Unreviewed
CVE-2026-4813
was published
Sep 1, 2026
Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox,...
Low
Unreviewed
CVE-2026-80201
was published
Aug 31, 2026
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due...
Critical
Unreviewed
CVE-2026-19286
was published
Aug 29, 2026
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute...
High
Unreviewed
CVE-2026-18729
was published
Aug 29, 2026
ProTip!
Advisories are also available from the
GraphQL API