GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
626 advisories
Filter by severity
LobsterAI 2026.5.27 through 2026.9.23 contains an external control of file path vulnerability in...
Moderate
Unreviewed
CVE-2026-108156
was published
Oct 9, 2026
datamodel-code-generator: Protobuf weak-import path traversal allows files to be written outside the temporary directory
High
CVE-2026-107377
was published
for
datamodel-code-generator
(pip)
Oct 8, 2026
PraisonAI: Project config can auto-save agent output outside the project root
Moderate
CVE-2026-60089
was published
for
praisonaiagents
(pip)
Oct 8, 2026
An arbitrary file manipulation vulnerability exists in the WebTools management interface of...
High
Unreviewed
CVE-2026-87685
was published
Oct 8, 2026
Docling has arbitrary file read/write (and command execution when shell-escape is enabled) when rendering untrusted TikZ with the opt-in Tectonic engine
High
CVE-2026-105744
was published
for
docling
(pip)
Oct 7, 2026
Docling: Crafted DoclingDocument JSON embeds local image files into converted output
Moderate
CVE-2026-105748
was published
for
docling
(pip)
Oct 7, 2026
Payload: Incomplete validation during the upload file lifecycle
High
CVE-2026-105865
was published
for
payload
(npm)
Oct 7, 2026
Ghost: Path Traversal via Locale Setting
Moderate
CVE-2026-105676
was published
for
ghost
(npm)
Oct 7, 2026
Backstage: Improper input validation in Confluence to Markdown scaffolder module
Moderate
CVE-2026-106559
was published
for
@backstage/plugin-scaffolder-backend-module-confluence-to-markdown
(npm)
Oct 7, 2026
Backstage: Improper input validation in cloud storage URL readers
Moderate
CVE-2026-106494
was published
for
@backstage/backend-defaults
(npm)
Oct 7, 2026
Quasar Framework: App Vite build cleanup can recursively remove unsafe configured output directories
Moderate
CVE-2026-106109
was published
for
@quasar/app-vite
(npm)
Oct 7, 2026
Quasar Framework: Path Traversal / Arbitrary File Write via crafted Icon Genie profile
High
CVE-2026-106103
was published
for
@quasar/icongenie
(npm)
Oct 7, 2026
An arbitrary file write vulnerability in the ClearPass Policy Manager OnGuard agent could allow...
Moderate
Unreviewed
CVE-2026-79814
was published
Oct 6, 2026
In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading...
Moderate
Unreviewed
CVE-2026-106219
was published
Oct 6, 2026
Nx: Path traversal in nx migrate package-migrations extraction
Moderate
CVE-2026-104853
was published
for
nx
(npm)
Oct 5, 2026
In Eclipse Che versions 7.29.0 and later, the GET `/api/scm/resolve` and `POST /api/factory...
High
Unreviewed
CVE-2026-86671
was published
Oct 5, 2026
DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load...
High
Unreviewed
CVE-2026-104809
was published
Oct 5, 2026
Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension...
Moderate
Unreviewed
CVE-2026-103511
was published
Oct 5, 2026
Perforce P4 Search prior to 2026.4.2 does not restrict file paths written through its logging...
High
Unreviewed
CVE-2026-103507
was published
Oct 5, 2026
- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows -...
Moderate
Unreviewed
CVE-2026-71453
was published
Oct 2, 2026
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a...
High
Unreviewed
CVE-2026-103255
was published
Oct 1, 2026
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File...
High
Unreviewed
CVE-2026-15983
was published
Oct 1, 2026
The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build...
High
Unreviewed
CVE-2026-19253
was published
Oct 1, 2026
The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate...
Critical
Unreviewed
CVE-2026-101148
was published
Oct 1, 2026
DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read...
High
Unreviewed
CVE-2026-103591
was published
Oct 1, 2026
ProTip!
Advisories are also available from the
GraphQL API