GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
626 advisories
Filter by severity
DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the...
High
Unreviewed
CVE-2026-90946
was published
Sep 14, 2026
LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core...
High
Unreviewed
CVE-2026-90932
was published
Sep 14, 2026
The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file...
Critical
Unreviewed
CVE-2026-77005
was published
Sep 12, 2026
The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path,...
Critical
Unreviewed
CVE-2026-77006
was published
Sep 12, 2026
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url
High
GHSA-wfgq-w7cq-qj7j
was published
for
mistralrs-server-core
(Rust)
Sep 10, 2026
n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
Moderate
CVE-2026-86995
was published
for
n8n
(npm)
Sep 10, 2026
Duplicate Advisory: Knowns Sandbox Escape: Unauthenticated Header Injection Grants AI Agent Unrestricted Access to Host Filesystem
Critical
GHSA-w47m-jpv2-qfw5
was published
for
knowns
(npm)
Sep 10, 2026
•
withdrawn
Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing...
High
Unreviewed
CVE-2026-86751
was published
Sep 9, 2026
Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field before rendering it...
High
Unreviewed
CVE-2026-86741
was published
Sep 9, 2026
SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff...
High
Unreviewed
CVE-2026-87815
was published
Sep 9, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
High
Unreviewed
CVE-2026-79692
was published
Sep 9, 2026
The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in...
Moderate
Unreviewed
CVE-2026-78620
was published
Sep 8, 2026
External control of file name or path in Skype for Business allows an unauthorized attacker to...
Critical
Unreviewed
CVE-2026-66302
was published
Sep 8, 2026
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
High
GHSA-2q42-4q24-7rgv
was published
for
@typespec/compiler
(npm)
Sep 8, 2026
Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
Moderate
GHSA-8m3c-c648-2xjj
was published
for
nodemailer
(npm)
Sep 8, 2026
Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path
High
CVE-2026-84374
was published
for
maatwebsite/excel
(Composer)
Sep 8, 2026
GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
High
CVE-2026-78677
was published
for
GitPython
(pip)
Sep 8, 2026
GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
High
CVE-2026-78675
was published
for
GitPython
(pip)
Sep 8, 2026
External control of file name or path in .NET allows an unauthorized attacker to elevate...
High
Unreviewed
CVE-2026-69805
was published
Sep 8, 2026
External control of file name or path in Windows Shell allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-69383
was published
Sep 8, 2026
External control of file name or path in Microsoft Exchange Server allows an authorized attacker...
High
Unreviewed
CVE-2026-69355
was published
Sep 8, 2026
External control of file name or path in Microsoft Office Word allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-62804
was published
Sep 8, 2026
NLTK: Stable FrameNet and NKJP readers parse outside-root XML
High
CVE-2026-62385
was published
for
nltk
(pip)
Sep 8, 2026
The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users...
Moderate
Unreviewed
CVE-2026-81830
was published
Sep 7, 2026
ProTip!
Advisories are also available from the
GraphQL API