GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,712
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,151
Rust
1,567
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
256 advisories
Filter by severity
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a...
High
Unreviewed
CVE-2026-86504
was published
Sep 7, 2026
Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path...
High
Unreviewed
CVE-2026-86169
was published
Sep 5, 2026
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs
Moderate
CVE-2026-45711
was published
for
github.com/axllent/mailpit
(Go)
May 19, 2026
A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a...
High
Unreviewed
CVE-2026-75569
was published
Aug 19, 2026
OpenStack Ironic Python Agent Includes Functionality from Untrusted Control Sphere
High
CVE-2026-43003
was published
for
ironic-python-agent
(pip)
May 1, 2026
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
High
CVE-2026-62680
was published
for
orval
(npm)
Sep 2, 2026
Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere...
High
Unreviewed
CVE-2026-58569
was published
Sep 1, 2026
A flaw was found in acm-operator-bundle. The build process for this component downloads and runs...
High
Unreviewed
CVE-2026-76139
was published
Aug 19, 2026
A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub...
Critical
Unreviewed
CVE-2026-71471
was published
Aug 13, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2...
High
Unreviewed
CVE-2026-18252
was published
Aug 26, 2026
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
High
CVE-2026-55522
was published
for
PraisonAI
(pip)
Aug 25, 2026
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
High
GHSA-ghvf-qf6h-g8x5
was published
for
@nocobase/server
(npm)
Aug 20, 2026
Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in...
Low
Unreviewed
CVE-2026-66843
was published
Aug 6, 2026
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
High
Unreviewed
CVE-2026-73367
was published
Aug 18, 2026
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
Moderate
CVE-2026-73851
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
High
CVE-2026-59867
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
CVE-2026-59865
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
Critical
CVE-2026-59864
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
CVE-2026-59863
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
pnpm: Repository-controlled configDependencies can select a pacquet native install engine
High
CVE-2026-55697
was published
for
pnpm
(npm)
Jun 26, 2026
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit...
High
Unreviewed
CVE-2026-6464
was published
Aug 13, 2026
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin...
High
Unreviewed
CVE-2026-18408
was published
Aug 13, 2026
when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase...
High
Unreviewed
CVE-2026-15560
was published
Aug 11, 2026
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
Moderate
CVE-2026-62902
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-arm64
(NuGet)
Aug 11, 2026
A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that...
High
Unreviewed
CVE-2021-41841
was published
Feb 10, 2022
ProTip!
Advisories are also available from the
GraphQL API