GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
405 advisories
Filter by severity
Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors
High
CVE-2026-61824
was published
for
defuddle
(npm)
Aug 21, 2026
Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username
Moderate
CVE-2026-63466
was published
for
unleash-server
(npm)
Aug 21, 2026
Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using...
Unknown
Unreviewed
CVE-2026-61398
was published
Aug 21, 2026
Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock...
Unknown
Unreviewed
CVE-2026-61399
was published
Aug 21, 2026
Laravel Backpack CRUD: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)
High
CVE-2026-54182
was published
for
backpack/crud
(Composer)
Aug 20, 2026
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25...
High
Unreviewed
CVE-2025-36254
was published
Aug 20, 2026
jmespath.php has CompilerRuntime code injection via unescaped function names
Critical
CVE-2026-54133
was published
for
mtdowling/jmespath.php
(Composer)
Aug 18, 2026
Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header...
Moderate
Unreviewed
CVE-2026-43971
was published
Aug 18, 2026
Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in...
Critical
Unreviewed
CVE-2026-73055
was published
Aug 16, 2026
dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting...
Moderate
Unreviewed
CVE-2026-73479
was published
Aug 14, 2026
gdu fails to strip terminal escape sequences from directory and file names when printing paths...
Moderate
Unreviewed
CVE-2026-73480
was published
Aug 13, 2026
HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient...
Low
Unreviewed
CVE-2025-62315
was published
Aug 13, 2026
is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a...
Moderate
Unreviewed
CVE-2026-48376
was published
Aug 11, 2026
GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing...
Moderate
Unreviewed
CVE-2026-66486
was published
Aug 10, 2026
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
Moderate
CVE-2026-70609
was published
for
electron
(npm)
Aug 5, 2026
CentreStack before 17.4 contains a session variable injection vulnerability that allows...
Moderate
Unreviewed
CVE-2026-54364
was published
Jul 30, 2026
mathlive's Lack of Escaping of HTML allows for XSS
Moderate
CVE-2026-54705
was published
for
mathlive
(npm)
Jul 29, 2026
diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting...
Moderate
Unreviewed
CVE-2026-50642
was published
Jul 29, 2026
Shescape: Home-directory disclosure in assignment context on Unix with Dash
Moderate
CVE-2026-73411
was published
for
shescape
(npm)
Jul 24, 2026
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
Moderate
GHSA-hc76-7mpc-qjqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
High
CVE-2026-73417
was published
for
jupyterlab
(pip)
Jul 22, 2026
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
Moderate
CVE-2026-64647
was published
for
next
(npm)
Jul 22, 2026
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
Moderate
CVE-2026-59895
was published
for
hono
(npm)
Jul 21, 2026
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
Low
CVE-2026-59727
was published
for
astro
(npm)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
Moderate
CVE-2026-50659
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API