GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
223 advisories
Filter by severity
Handlebars: JavaScript Injection via Own Property Check Bypass
Critical
CVE-2026-106445
was published
for
handlebars
(npm)
Oct 8, 2026
Ghost: Private IP Filtering Bypass via IPv6 Transition Addresses
Moderate
CVE-2026-105648
was published
for
ghost
(npm)
Oct 7, 2026
Ghost: Stored XSS via oEmbed Photo Responses
High
CVE-2026-105650
was published
for
ghost
(npm)
Oct 7, 2026
Hydra instantiate target blacklist bypasses permit code execution
High
CVE-2026-106442
was published
for
hydra-core
(pip)
Oct 7, 2026
In JetBrains TeamCity before 2026.1.3
2025.11.7 kotlin DSL sandbox escape leading to RCE on the...
High
Unreviewed
CVE-2026-106218
was published
Oct 6, 2026
simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection
Critical
CVE-2026-102829
was published
for
@simple-git/argv-parser
(npm)
Oct 5, 2026
simple-git unsafe-operation guard does not block trailer command configuration
Critical
CVE-2026-102828
was published
for
simple-git
(npm)
Oct 5, 2026
OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system...
High
Unreviewed
CVE-2026-101882
was published
Sep 30, 2026
OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in...
High
Unreviewed
CVE-2026-101884
was published
Sep 30, 2026
In JetBrains TeamCity before 2026.2,
2026.1.4,
2025.11.8 sandbox escape leading to code...
High
Unreviewed
CVE-2026-100253
was published
Sep 30, 2026
@bytebase/dbhub's read-only mode does not prevent database writes
High
CVE-2026-61788
was published
for
@bytebase/dbhub
(npm)
Sep 24, 2026
In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header...
Moderate
Unreviewed
CVE-2026-97149
was published
Sep 24, 2026
A flaw was found in the automation-controller input-validation
guard...
High
Unreviewed
CVE-2026-84714
was published
Sep 23, 2026
A flaw was found in Ansible Automation Platform's automation-controller. The custom
Credential...
High
Unreviewed
CVE-2026-84706
was published
Sep 23, 2026
A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist...
Critical
Unreviewed
CVE-2026-75884
was published
Sep 23, 2026
openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that...
High
Unreviewed
CVE-2026-67615
was published
Sep 22, 2026
MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud)
High
CVE-2026-77251
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny...
High
Unreviewed
CVE-2026-93598
was published
Sep 18, 2026
@nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration
High
CVE-2026-63671
was published
for
@nuxtjs/mdc
(npm)
Sep 16, 2026
Grav: XSS Blueprint Validation Bypass via Twig String Concatenation
Moderate
CVE-2026-61453
was published
for
getgrav/grav
(Composer)
Sep 16, 2026
IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to...
Moderate
Unreviewed
CVE-2026-11918
was published
Sep 15, 2026
An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command...
Critical
Unreviewed
CVE-2026-87985
was published
Sep 11, 2026
PocketMine-MP versions before 5.43.1 fail to properly validate the Certificate field during...
High
Unreviewed
CVE-2026-86199
was published
Sep 9, 2026
A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python...
Critical
Unreviewed
CVE-2026-79696
was published
Sep 9, 2026
Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command...
High
Unreviewed
CVE-2026-82536
was published
Sep 8, 2026
ProTip!
Advisories are also available from the
GraphQL API