GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,714
Maven
5,000+
npm
5,000+
NuGet
1,110
pip
5,000+
Pub
13
RubyGems
1,151
Rust
1,567
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
257 advisories
Filter by severity
A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that...
High
Unreviewed
CVE-2021-41841
was published
Feb 10, 2022
In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the...
High
Unreviewed
CVE-2021-33626
was published
May 24, 2022
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
High
Unreviewed
CVE-2026-67623
was published
Aug 5, 2026
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe...
High
Unreviewed
CVE-2026-66141
was published
Jul 24, 2026
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python...
High
Unreviewed
CVE-2026-65908
was published
Jul 23, 2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project...
High
Unreviewed
CVE-2026-64806
was published
Jul 23, 2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project...
High
Unreviewed
CVE-2026-64804
was published
Jul 23, 2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project...
High
Unreviewed
CVE-2026-64805
was published
Jul 23, 2026
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project...
High
Unreviewed
CVE-2026-64808
was published
Jul 23, 2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied...
High
Unreviewed
CVE-2026-64807
was published
Jul 23, 2026
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting...
High
Unreviewed
CVE-2026-64811
was published
Jul 23, 2026
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project...
High
Unreviewed
CVE-2026-64809
was published
Jul 23, 2026
containerd: CRI checkpoint import allows local image tag poisoning
Moderate
CVE-2026-50195
was published
for
github.com/containerd/containerd/v2
(Go)
Jun 19, 2026
huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path
High
CVE-2026-5241
was published
for
transformers
(pip)
Jun 3, 2026
Pi Agent: Pi loads project-local extensions without approval
Moderate
CVE-2026-54325
was published
for
@earendil-works/pi-coding-agent
(npm)
Jun 17, 2026
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the...
Low
Unreviewed
CVE-2026-16085
was published
Jul 18, 2026
ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes...
High
Unreviewed
CVE-2026-57860
was published
Jul 17, 2026
OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of...
High
Unreviewed
CVE-2026-62222
was published
Jul 17, 2026
Cherry Studio versions 1.2.2 through 1.9.12, fixed in commit 1518530, contain a remote code...
High
Unreviewed
CVE-2026-40501
was published
Jul 15, 2026
NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper...
Moderate
Unreviewed
CVE-2026-24226
was published
Jul 14, 2026
A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the...
Low
Unreviewed
CVE-2026-15519
was published
Jul 13, 2026
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Moderate
CVE-2026-42510
was published
for
ironic
(pip)
Apr 28, 2026
yeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation
High
CVE-2026-42089
was published
for
yeoman-environment
(npm)
May 26, 2026
OpenClaw's marketplace runtime extension metadata could point at unscanned payloads
High
CVE-2026-53810
was published
for
openclaw
(npm)
Jul 2, 2026
Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`
High
CVE-2026-49986
was published
for
neuro-cortex-memory
(pip)
Jul 1, 2026
ProTip!
Advisories are also available from the
GraphQL API