GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
9,657 advisories
Filter by severity
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19...
Critical
Unreviewed
CVE-2026-85706
was published
Sep 12, 2026
An interface that accepts file uploads from authenticated users extracts the contents of uploaded...
High
Unreviewed
CVE-2026-90445
was published
Sep 12, 2026
@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
Moderate
CVE-2026-59149
was published
for
@mockoon/cli
(npm)
Sep 11, 2026
When tarfile extracts a link on a system that doesn't support links, it falls back to extracting...
Moderate
Unreviewed
CVE-2026-87910
was published
Sep 11, 2026
An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an...
Critical
Unreviewed
CVE-2026-87983
was published
Sep 11, 2026
An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an...
Critical
Unreviewed
CVE-2026-87984
was published
Sep 11, 2026
a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an...
Moderate
Unreviewed
CVE-2026-87727
was published
Sep 11, 2026
The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and...
High
Unreviewed
CVE-2026-19991
was published
Sep 11, 2026
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
High
Unreviewed
CVE-2026-77807
was published
Sep 11, 2026
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to...
Moderate
Unreviewed
CVE-2026-86087
was published
Sep 11, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause...
Critical
Unreviewed
CVE-2026-82100
was published
Sep 11, 2026
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute...
High
Unreviewed
CVE-2026-84889
was published
Sep 11, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to...
High
Unreviewed
CVE-2026-81551
was published
Sep 11, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain...
High
Unreviewed
CVE-2026-81554
was published
Sep 11, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to...
High
Unreviewed
CVE-2026-81540
was published
Sep 11, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create...
Critical
Unreviewed
CVE-2026-80424
was published
Sep 11, 2026
Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor...
High
Unreviewed
CVE-2025-57231
was published
Sep 11, 2026
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
Moderate
CVE-2026-88014
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
rclone: source object names can escape the configured root on upload
Moderate
CVE-2026-88046
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
An
authenticated directory traversal vulnerability in file upload functionality has
been...
Moderate
Unreviewed
CVE-2026-76652
was published
Sep 10, 2026
n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
Moderate
CVE-2026-86995
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
Moderate
CVE-2026-86079
was published
for
n8n
(npm)
Sep 10, 2026
knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint...
Moderate
Unreviewed
CVE-2026-88940
was published
Sep 10, 2026
knowns through 0.33.0 fails to properly validate template destination paths in the code...
High
Unreviewed
CVE-2026-88937
was published
Sep 10, 2026
knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project...
High
Unreviewed
CVE-2026-88938
was published
Sep 10, 2026
ProTip!
Advisories are also available from the
GraphQL API