GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
9,657 advisories
Filter by severity
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
High
Unreviewed
CVE-2026-80131
was published
Sep 7, 2026
The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated...
Moderate
Unreviewed
CVE-2026-78043
was published
Sep 7, 2026
nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show()...
High
Unreviewed
CVE-2026-86258
was published
Sep 6, 2026
h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic()....
High
Unreviewed
CVE-2026-86253
was published
Sep 6, 2026
h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A...
High
Unreviewed
CVE-2026-86251
was published
Sep 6, 2026
RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a...
High
Unreviewed
CVE-2026-67281
was published
Sep 5, 2026
The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value...
Moderate
Unreviewed
CVE-2026-84898
was published
Sep 5, 2026
The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up...
Moderate
Unreviewed
CVE-2026-14975
was published
Sep 5, 2026
The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path...
Low
Unreviewed
CVE-2025-15693
was published
Sep 5, 2026
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and...
Critical
Unreviewed
CVE-2026-81939
was published
Sep 4, 2026
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain...
Moderate
Unreviewed
CVE-2026-17622
was published
Sep 4, 2026
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on...
Moderate
Unreviewed
CVE-2026-17621
was published
Sep 4, 2026
IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse...
Moderate
Unreviewed
CVE-2026-14470
was published
Sep 4, 2026
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain...
Moderate
Unreviewed
CVE-2026-19302
was published
Sep 4, 2026
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete...
High
Unreviewed
CVE-2026-19303
was published
Sep 4, 2026
IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files...
High
Unreviewed
CVE-2026-19306
was published
Sep 4, 2026
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain...
Moderate
Unreviewed
CVE-2026-19299
was published
Sep 4, 2026
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
High
CVE-2026-75859
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
High
CVE-2026-75914
was published
for
codewhale
(npm)
Sep 4, 2026
IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write...
Moderate
Unreviewed
CVE-2026-9138
was published
Sep 4, 2026
Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows...
High
Unreviewed
CVE-2026-85690
was published
Sep 4, 2026
AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace...
High
Unreviewed
CVE-2026-85685
was published
Sep 4, 2026
excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is...
Critical
Unreviewed
CVE-2026-85661
was published
Sep 4, 2026
Bruno versions through 3.4.2 fail to validate file paths in request body declarations, allowing...
High
Unreviewed
CVE-2026-85665
was published
Sep 4, 2026
firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the...
High
Unreviewed
CVE-2026-85606
was published
Sep 4, 2026
ProTip!
Advisories are also available from the
GraphQL API