GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
3,915 advisories
Filter by severity
This
vulnerability exists in the Netlink ICT HG323RW router due to insufficient
authorization and...
High
Unreviewed
CVE-2026-96515
was published
Sep 24, 2026
Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the ...
Critical
Unreviewed
CVE-2026-93352
was published
Sep 24, 2026
Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This...
High
Unreviewed
CVE-2026-5695
was published
Sep 23, 2026
An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index...
High
Unreviewed
CVE-2026-88419
was published
Sep 22, 2026
Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the...
High
Unreviewed
CVE-2026-88738
was published
Sep 22, 2026
Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2...
High
Unreviewed
CVE-2026-36467
was published
Sep 21, 2026
The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or...
Critical
Unreviewed
CVE-2026-82187
was published
Sep 21, 2026
Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft...
Critical
Unreviewed
CVE-2026-88857
was published
Sep 20, 2026
NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi(...
High
Unreviewed
CVE-2026-94104
was published
Sep 20, 2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly...
High
Unreviewed
CVE-2026-81650
was published
Sep 20, 2026
The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or...
Moderate
Unreviewed
CVE-2026-84750
was published
Sep 19, 2026
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up...
Critical
Unreviewed
CVE-2026-84434
was published
Sep 19, 2026
The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for...
High
Unreviewed
CVE-2026-93031
was published
Sep 18, 2026
ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated...
High
Unreviewed
CVE-2026-77929
was published
Sep 18, 2026
HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to...
Moderate
Unreviewed
CVE-2026-56590
was published
Sep 18, 2026
Chamilo LMS CStudio upload flow allows unauthenticated remote code execution
Critical
CVE-2026-45140
was published
for
chamilo/chamilo-lms
(Composer)
Sep 17, 2026
HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows...
High
Unreviewed
CVE-2026-92980
was published
Sep 17, 2026
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload...
Critical
Unreviewed
CVE-2026-87796
was published
Sep 17, 2026
The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up...
High
Unreviewed
CVE-2026-87935
was published
Sep 17, 2026
The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or...
High
Unreviewed
CVE-2026-76552
was published
Sep 16, 2026
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress...
High
Unreviewed
CVE-2026-78088
was published
Sep 16, 2026
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of...
High
Unreviewed
CVE-2026-81236
was published
Sep 15, 2026
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of...
High
Unreviewed
CVE-2026-81239
was published
Sep 15, 2026
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of...
High
Unreviewed
CVE-2026-81240
was published
Sep 15, 2026
Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication...
High
Unreviewed
CVE-2026-82793
was published
Sep 14, 2026
ProTip!
Advisories are also available from the
GraphQL API