GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
3,915 advisories
Filter by severity
Contributor Arbitrary File Upload in Creator LMS <= 1.2.21 versions.
Critical
Unreviewed
CVE-2026-62129
was published
Oct 10, 2026
Subscriber Arbitrary File Upload in CodeBard Help Desk <= 1.1.2 versions.
Critical
Unreviewed
CVE-2026-62024
was published
Oct 10, 2026
Unauthenticated Arbitrary File Upload in Tailored Tools <= 3.0.3 versions.
Critical
Unreviewed
CVE-2026-62025
was published
Oct 10, 2026
The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to...
High
Unreviewed
CVE-2026-83526
was published
Oct 10, 2026
The Rank Math SEO WordPress plugin before 1.0.280 does not correctly validate the type of a file...
High
Unreviewed
CVE-2026-104752
was published
Oct 10, 2026
The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code...
Critical
Unreviewed
CVE-2026-103889
was published
Oct 10, 2026
The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for...
Critical
Unreviewed
CVE-2026-94589
was published
Oct 10, 2026
ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI...
High
Unreviewed
CVE-2026-108113
was published
Oct 9, 2026
HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in...
High
Unreviewed
CVE-2026-108101
was published
Oct 9, 2026
Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows...
Critical
Unreviewed
CVE-2026-94503
was published
Oct 9, 2026
The AWP Classifieds WordPress plugin before 4.4.9 does not validate the type of files extracted...
High
Unreviewed
CVE-2025-15700
was published
Oct 9, 2026
Unrestricted upload of file with dangerous type vulnerability in İzometri IT Services Domestic...
High
Unreviewed
CVE-2026-91844
was published
Oct 8, 2026
The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in...
Critical
Unreviewed
CVE-2026-85097
was published
Oct 8, 2026
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary...
Critical
Unreviewed
CVE-2026-17609
was published
Oct 8, 2026
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Unrestricted...
High
Unreviewed
CVE-2026-17196
was published
Oct 8, 2026
Ghost : Stored XSS via SVG Files in Content Imports
Moderate
CVE-2026-105644
was published
for
ghost
(npm)
Oct 7, 2026
Ghost: Stored XSS via SVG Uploads Bypassing Sanitization
High
CVE-2026-105649
was published
for
ghost
(npm)
Oct 7, 2026
Payload: Bypassed sanitization of user uploaded SVGs
High
CVE-2026-105862
was published
for
payload
(npm)
Oct 7, 2026
Payload: Uploaded XML files could execute same-origin JavaScript
High
CVE-2026-105868
was published
for
payload
(npm)
Oct 7, 2026
Ghost: Stored XSS via Bookmark Card Images
High
CVE-2026-105651
was published
for
ghost
(npm)
Oct 7, 2026
Ghost: Stored XSS via File Uploads on Local Storage
High
CVE-2026-105679
was published
for
ghost
(npm)
Oct 7, 2026
Kunstmaan CMS: MediaBundle extension blacklist bypass allows authenticated administrators to upload executable PHP files leading to remote code execution
High
CVE-2026-104890
was published
for
kunstmaan/bundles-cms
(Composer)
Oct 7, 2026
Unrestricted file upload vulnerability in the BugTracker.NET attachment functionality. An...
High
Unreviewed
CVE-2026-92532
was published
Oct 7, 2026
HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport()...
High
Unreviewed
CVE-2026-104069
was published
Oct 6, 2026
Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions.
Critical
Unreviewed
CVE-2026-39755
was published
Oct 6, 2026
ProTip!
Advisories are also available from the
GraphQL API