GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
1,478 advisories
Filter by severity
Contributor Arbitrary File Upload in Creator LMS <= 1.2.21 versions.
Critical
Unreviewed
CVE-2026-62129
was published
Oct 10, 2026
Subscriber Arbitrary File Upload in CodeBard Help Desk <= 1.1.2 versions.
Critical
Unreviewed
CVE-2026-62024
was published
Oct 10, 2026
Unauthenticated Arbitrary File Upload in Tailored Tools <= 3.0.3 versions.
Critical
Unreviewed
CVE-2026-62025
was published
Oct 10, 2026
The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code...
Critical
Unreviewed
CVE-2026-103889
was published
Oct 10, 2026
The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for...
Critical
Unreviewed
CVE-2026-94589
was published
Oct 10, 2026
Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows...
Critical
Unreviewed
CVE-2026-94503
was published
Oct 9, 2026
The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in...
Critical
Unreviewed
CVE-2026-85097
was published
Oct 8, 2026
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary...
Critical
Unreviewed
CVE-2026-17609
was published
Oct 8, 2026
Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions.
Critical
Unreviewed
CVE-2026-39770
was published
Oct 6, 2026
Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions.
Critical
Unreviewed
CVE-2026-39755
was published
Oct 6, 2026
Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions.
Critical
Unreviewed
CVE-2026-39757
was published
Oct 6, 2026
Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions.
Critical
Unreviewed
CVE-2026-39759
was published
Oct 6, 2026
Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions.
Critical
Unreviewed
CVE-2026-32579
was published
Oct 6, 2026
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain
Critical
GHSA-v2f8-6655-7grj
was published
for
vibe-trading-ai
(pip)
Oct 2, 2026
H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an...
Critical
Unreviewed
CVE-2023-54405
was published
Oct 2, 2026
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK <...
Critical
Unreviewed
CVE-2026-102427
was published
Sep 30, 2026
The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on...
Critical
Unreviewed
CVE-2026-75873
was published
Sep 30, 2026
The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an...
Critical
Unreviewed
CVE-2026-70356
was published
Sep 30, 2026
Unrestricted Upload of File with Dangerous Type in the
/WebAgenda/download/uploadFile.jsp API...
Critical
Unreviewed
CVE-2026-96431
was published
Sep 29, 2026
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload...
Critical
Unreviewed
CVE-2026-82901
was published
Sep 26, 2026
Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature...
Critical
Unreviewed
CVE-2026-94132
was published
Sep 26, 2026
The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload...
Critical
Unreviewed
CVE-2026-18143
was published
Sep 26, 2026
GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP...
Critical
Unreviewed
CVE-2026-100389
was published
Sep 25, 2026
Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the ...
Critical
Unreviewed
CVE-2026-93352
was published
Sep 24, 2026
The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or...
Critical
Unreviewed
CVE-2026-82187
was published
Sep 21, 2026
ProTip!
Advisories are also available from the
GraphQL API