GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
5,657 advisories
Filter by severity
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due...
Critical
Unreviewed
CVE-2026-19286
was published
Aug 29, 2026
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute...
High
Unreviewed
CVE-2026-18729
was published
Aug 29, 2026
BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once...
High
Unreviewed
CVE-2026-82278
was published
Aug 28, 2026
Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that...
High
Unreviewed
CVE-2026-77939
was published
Aug 28, 2026
Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name
Critical
CVE-2026-55634
was published
for
pimcore/pimcore
(Composer)
Aug 28, 2026
CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on...
High
Unreviewed
CVE-2026-76148
was published
Aug 28, 2026
Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)
Critical
CVE-2026-55565
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
Critical
CVE-2026-55559
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`
Critical
CVE-2026-55511
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
High
CVE-2026-54757
was published
for
compliance-trestle
(pip)
Aug 28, 2026
Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling...
Critical
Unreviewed
CVE-2026-82244
was published
Aug 28, 2026
ServiceNow has remediated a sandbox escape security issue that was identified in the Now Platform...
High
Unreviewed
CVE-2026-6876
was published
Aug 27, 2026
ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI...
Critical
Unreviewed
CVE-2026-18885
was published
Aug 27, 2026
openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls:...
Critical
Unreviewed
CVE-2026-81719
was published
Aug 27, 2026
ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that...
Critical
Unreviewed
CVE-2026-81096
was published
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
High
CVE-2026-54721
was published
for
silverstripe/userforms
(Composer)
Aug 27, 2026
The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network...
High
Unreviewed
CVE-2026-19223
was published
Aug 27, 2026
The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to...
Moderate
Unreviewed
CVE-2026-19225
was published
Aug 27, 2026
whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands...
High
Unreviewed
CVE-2026-58474
was published
Aug 26, 2026
The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against...
High
Unreviewed
CVE-2026-74851
was published
Aug 26, 2026
Code injection in Bisection in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to...
Moderate
Unreviewed
CVE-2026-79249
was published
Aug 25, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local...
High
Unreviewed
CVE-2026-65082
was published
Aug 25, 2026
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
High
GHSA-vwf3-4xxj-qg6h
was published
for
mcp-contextforge-gateway
(pip)
Aug 25, 2026
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
High
CVE-2026-55585
was published
for
qwed
(pip)
Aug 25, 2026
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
Critical
CVE-2026-55546
was published
for
qwed-mcp
(pip)
Aug 25, 2026
ProTip!
Advisories are also available from the
GraphQL API