GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
3,915 advisories
Filter by severity
Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions.
Critical
Unreviewed
CVE-2026-39755
was published
Oct 6, 2026
Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions.
Critical
Unreviewed
CVE-2026-39757
was published
Oct 6, 2026
Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions.
Critical
Unreviewed
CVE-2026-39759
was published
Oct 6, 2026
Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions.
Critical
Unreviewed
CVE-2026-32579
was published
Oct 6, 2026
The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up...
High
Unreviewed
CVE-2026-105701
was published
Oct 6, 2026
W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that...
High
Unreviewed
CVE-2026-105123
was published
Oct 4, 2026
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain
Critical
GHSA-v2f8-6655-7grj
was published
for
vibe-trading-ai
(pip)
Oct 2, 2026
H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an...
Critical
Unreviewed
CVE-2023-54405
was published
Oct 2, 2026
YesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated...
High
Unreviewed
CVE-2026-104471
was published
Oct 2, 2026
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in...
High
Unreviewed
CVE-2026-92820
was published
Oct 2, 2026
Incomplete extension blacklist in the File Manager module allows authenticated upload and...
High
Unreviewed
CVE-2026-64949
was published
Oct 1, 2026
An unrestricted file upload vulnerability caused by insufficient file extension and integrity...
Low
Unreviewed
CVE-2026-76144
was published
Oct 1, 2026
yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions...
High
Unreviewed
CVE-2026-103474
was published
Sep 30, 2026
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK <...
Critical
Unreviewed
CVE-2026-102427
was published
Sep 30, 2026
EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote...
High
Unreviewed
CVE-2026-102454
was published
Sep 30, 2026
The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on...
Critical
Unreviewed
CVE-2026-75873
was published
Sep 30, 2026
The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an...
Critical
Unreviewed
CVE-2026-70356
was published
Sep 30, 2026
Unrestricted Upload of File with Dangerous Type in the
/WebAgenda/download/uploadFile.jsp API...
Critical
Unreviewed
CVE-2026-96431
was published
Sep 29, 2026
mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints...
Low
Unreviewed
CVE-2026-102366
was published
Sep 29, 2026
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via...
High
Unreviewed
CVE-2026-12264
was published
Sep 28, 2026
Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade...
High
Unreviewed
CVE-2026-85134
was published
Sep 28, 2026
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload...
Critical
Unreviewed
CVE-2026-82901
was published
Sep 26, 2026
Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature...
Critical
Unreviewed
CVE-2026-94132
was published
Sep 26, 2026
The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload...
Critical
Unreviewed
CVE-2026-18143
was published
Sep 26, 2026
GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP...
Critical
Unreviewed
CVE-2026-100389
was published
Sep 25, 2026
ProTip!
Advisories are also available from the
GraphQL API