GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
574 advisories
Filter by severity
The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file...
Critical
Unreviewed
CVE-2026-77005
was published
Sep 12, 2026
The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path,...
Critical
Unreviewed
CVE-2026-77006
was published
Sep 12, 2026
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url
High
GHSA-wfgq-w7cq-qj7j
was published
for
mistralrs-server-core
(Rust)
Sep 10, 2026
n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
Moderate
CVE-2026-86995
was published
for
n8n
(npm)
Sep 10, 2026
knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header...
Critical
Unreviewed
CVE-2026-88899
was published
Sep 10, 2026
Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing...
High
Unreviewed
CVE-2026-86751
was published
Sep 9, 2026
Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field before rendering it...
High
Unreviewed
CVE-2026-86741
was published
Sep 9, 2026
SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff...
High
Unreviewed
CVE-2026-87815
was published
Sep 9, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
High
Unreviewed
CVE-2026-79692
was published
Sep 9, 2026
The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in...
Moderate
Unreviewed
CVE-2026-78620
was published
Sep 8, 2026
External control of file name or path in Skype for Business allows an unauthorized attacker to...
Critical
Unreviewed
CVE-2026-66302
was published
Sep 8, 2026
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
High
GHSA-2q42-4q24-7rgv
was published
for
@typespec/compiler
(npm)
Sep 8, 2026
Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
Moderate
GHSA-8m3c-c648-2xjj
was published
for
nodemailer
(npm)
Sep 8, 2026
Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path
High
CVE-2026-84374
was published
for
maatwebsite/excel
(Composer)
Sep 8, 2026
GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
High
CVE-2026-78677
was published
for
GitPython
(pip)
Sep 8, 2026
GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
High
CVE-2026-78675
was published
for
GitPython
(pip)
Sep 8, 2026
External control of file name or path in .NET allows an unauthorized attacker to elevate...
High
Unreviewed
CVE-2026-69805
was published
Sep 8, 2026
External control of file name or path in Windows Shell allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-69383
was published
Sep 8, 2026
External control of file name or path in Microsoft Exchange Server allows an authorized attacker...
High
Unreviewed
CVE-2026-69355
was published
Sep 8, 2026
External control of file name or path in Microsoft Office Word allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-62804
was published
Sep 8, 2026
NLTK: Stable FrameNet and NKJP readers parse outside-root XML
High
CVE-2026-62385
was published
for
nltk
(pip)
Sep 8, 2026
The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users...
Moderate
Unreviewed
CVE-2026-81830
was published
Sep 7, 2026
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows...
Critical
Unreviewed
CVE-2026-86189
was published
Sep 5, 2026
An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB...
High
Unreviewed
CVE-2026-79426
was published
Sep 4, 2026
ProTip!
Advisories are also available from the
GraphQL API