GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
5,919 advisories
Filter by severity
Unauthenticated Content Injection in Boutique <= 2.3.3 versions.
Moderate
Unreviewed
CVE-2026-62098
was published
Oct 10, 2026
Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration &...
Critical
Unreviewed
CVE-2026-42696
was published
Oct 10, 2026
Unauthenticated Remote Code Execution (RCE) in Everest Backup <= 2.3.13 versions.
High
Unreviewed
CVE-2026-39802
was published
Oct 10, 2026
Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows...
Critical
Unreviewed
CVE-2026-108598
was published
Oct 10, 2026
9router 0.4.1 through 0.5.99 contains a configuration injection vulnerability in the POST /api...
High
Unreviewed
CVE-2026-108593
was published
Oct 10, 2026
Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme Thank You...
High
Unreviewed
CVE-2026-103071
was published
Oct 10, 2026
openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows...
Critical
Unreviewed
CVE-2026-108551
was published
Oct 10, 2026
The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all...
Critical
Unreviewed
CVE-2026-97670
was published
Oct 10, 2026
The Fastcache by Host.it plugin for WordPress is vulnerable to Code Injection in all versions up...
High
Unreviewed
CVE-2026-104021
was published
Oct 10, 2026
Tina: Code injection via unescaped Git branch name in generated client source
High
CVE-2026-108259
was published
for
@tinacms/cli
(npm)
Oct 9, 2026
Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite
Critical
CVE-2026-107806
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Oct 9, 2026
SmarterMail before build 9777 contains a remote code execution vulnerability that allows an...
High
Unreviewed
CVE-2026-104082
was published
Oct 9, 2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0...
Moderate
Unreviewed
CVE-2026-11888
was published
Oct 8, 2026
dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote...
Critical
Unreviewed
CVE-2026-107700
was published
Oct 8, 2026
PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
High
CVE-2026-61433
was published
for
praisonai
(pip)
Oct 8, 2026
Handlebars: JavaScript Injection via AST Type Confusion in compile (bypass of CVE-2026-33937)
Critical
CVE-2026-106446
was published
for
handlebars
(npm)
Oct 8, 2026
PraisonAI: Plugin Auto-Discovery Executes Arbitrary Python Files Without Verification
High
CVE-2026-61446
was published
for
praisonaiagents
(pip)
Oct 8, 2026
PraisonAI: CodeAgent Executes LLM-Generated Code Without Sandboxing and Leaks All Environment Secrets
Critical
CVE-2026-61447
was published
for
praisonaiagents
(pip)
Oct 8, 2026
ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a code injection vulnerability in...
Moderate
Unreviewed
CVE-2026-105404
was published
Oct 8, 2026
Ghost: Remote Code Execution via Bookmark Card Images
High
CVE-2026-105642
was published
for
ghost
(npm)
Oct 7, 2026
Payload: Remote Code Execution through first-register
High
CVE-2026-105858
was published
for
payload
(npm)
Oct 7, 2026
Payload Form Builder has an RCE issue
Critical
CVE-2026-105857
was published
for
@payloadcms/plugin-form-builder
(npm)
Oct 7, 2026
Ghost: Remote Code Execution via Theme Translation Files
High
CVE-2026-105677
was published
for
ghost
(npm)
Oct 7, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering...
High
Unreviewed
CVE-2026-76484
was published
Oct 7, 2026
Hydra logging configuration permits unsafe callable resolution
High
CVE-2026-106441
was published
for
hydra-core
(pip)
Oct 7, 2026
ProTip!
Advisories are also available from the
GraphQL API