GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
3,915 advisories
Filter by severity
Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a...
High
Unreviewed
CVE-2026-82780
was published
Sep 14, 2026
HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.
Moderate
Unreviewed
CVE-2023-34854
was published
Sep 14, 2026
The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type...
Critical
Unreviewed
CVE-2026-84171
was published
Sep 12, 2026
The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce...
Critical
Unreviewed
CVE-2026-81402
was published
Sep 12, 2026
The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin...
Critical
Unreviewed
CVE-2026-8778
was published
Sep 11, 2026
The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass...
Moderate
Unreviewed
CVE-2026-12215
was published
Sep 11, 2026
BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with...
High
Unreviewed
CVE-2026-84063
was published
Sep 10, 2026
The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary...
Critical
Unreviewed
CVE-2026-18351
was published
Sep 10, 2026
An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0....
Critical
Unreviewed
CVE-2026-71805
was published
Sep 10, 2026
MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the...
Moderate
Unreviewed
CVE-2026-87928
was published
Sep 9, 2026
Rara One Click Demo Import plugin for WordPress before 1.3.5 contains an arbitrary file upload...
High
Unreviewed
CVE-2026-26212
was published
Sep 9, 2026
A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173)...
High
Unreviewed
CVE-2026-50093
was published
Sep 8, 2026
easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the...
Critical
Unreviewed
CVE-2026-50894
was published
Sep 4, 2026
An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attackers to execute...
High
Unreviewed
CVE-2026-78839
was published
Sep 4, 2026
File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote attacker to execute...
High
Unreviewed
CVE-2026-71620
was published
Sep 4, 2026
An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solutions X-Serie Gateway...
High
Unreviewed
CVE-2026-75169
was published
Sep 4, 2026
Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability...
Critical
Unreviewed
CVE-2026-44402
was published
Sep 4, 2026
The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions...
High
Unreviewed
CVE-2026-12483
was published
Sep 4, 2026
Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports...
Critical
Unreviewed
CVE-2026-76174
was published
Sep 3, 2026
UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated...
High
Unreviewed
CVE-2026-82524
was published
Sep 2, 2026
The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files...
Critical
Unreviewed
CVE-2026-4357
was published
Sep 2, 2026
The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file...
Critical
Unreviewed
CVE-2025-9314
was published
Sep 2, 2026
Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
High
Unreviewed
CVE-2026-76782
was published
Sep 2, 2026
elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)
High
CVE-2026-81891
was published
for
Studio-42/elFinder
(Composer)
Sep 2, 2026
Malicious calendar invitations could use file URI attachments to launch local or network-hosted...
Critical
Unreviewed
CVE-2026-84637
was published
Sep 2, 2026
ProTip!
Advisories are also available from the
GraphQL API