GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
675 advisories
Filter by severity
Local privilege escalation in Checkmk 2.5.0 before 2.5.0p10 allows a user with access to edit the...
Moderate
Unreviewed
CVE-2026-105331
was published
Oct 8, 2026
Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend
High
CVE-2026-106505
was published
for
@backstage/plugin-techdocs-node
(npm)
Oct 7, 2026
A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a...
High
Unreviewed
CVE-2026-59265
was published
Oct 2, 2026
Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource...
High
Unreviewed
CVE-2026-19547
was published
Sep 29, 2026
In Google fuse-archive versions prior to 1.24, an attacker who can prepend a directory to PATH or...
Moderate
Unreviewed
CVE-2026-87723
was published
Sep 28, 2026
OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell...
Moderate
Unreviewed
CVE-2026-100584
was published
Sep 26, 2026
GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the...
High
Unreviewed
CVE-2026-100310
was published
Sep 25, 2026
An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before...
High
Unreviewed
CVE-2026-68492
was published
Sep 23, 2026
n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git...
Moderate
Unreviewed
CVE-2026-92587
was published
Sep 17, 2026
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
High
CVE-2026-81192
was published
for
OpenTelemetry.Resources.Host
(NuGet)
Sep 16, 2026
Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app...
Moderate
Unreviewed
CVE-2026-0307
was published
Sep 10, 2026
Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in...
Moderate
Unreviewed
CVE-2026-80159
was published
Sep 8, 2026
The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within...
High
Unreviewed
CVE-2026-78574
was published
Sep 8, 2026
Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges...
High
Unreviewed
CVE-2026-69785
was published
Sep 8, 2026
Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges...
High
Unreviewed
CVE-2026-69328
was published
Sep 8, 2026
OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local...
High
Unreviewed
CVE-2026-84226
was published
Sep 7, 2026
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
High
CVE-2026-78680
was published
for
nltk
(pip)
Sep 1, 2026
Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root,...
High
Unreviewed
CVE-2026-82862
was published
Aug 31, 2026
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative...
High
Unreviewed
CVE-2026-81697
was published
Aug 27, 2026
Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in...
High
Unreviewed
CVE-2026-75768
was published
Aug 25, 2026
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
High
CVE-2026-55522
was published
for
PraisonAI
(pip)
Aug 25, 2026
Duplicate Advisory: Uncontrolled search path when invoking the Graphviz 'dot' binary (CWE-426/CWE-427)
High
GHSA-54xp-3ww7-6wjg
was published
for
nltk
(pip)
Aug 25, 2026
•
withdrawn
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to...
Critical
Unreviewed
CVE-2026-78155
was published
Aug 23, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary...
High
Unreviewed
CVE-2026-16869
was published
Aug 19, 2026
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the...
Critical
Unreviewed
CVE-2026-74872
was published
Aug 17, 2026
ProTip!
Advisories are also available from the
GraphQL API