GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
118
GitHub Actions
56
Go
4,844
Maven
5,000+
npm
5,000+
NuGet
1,129
pip
5,000+
Pub
13
RubyGems
1,157
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
5,812 advisories
Filter by severity
Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)
High
CVE-2026-57170
was published
for
compliance-trestle
(pip)
Sep 24, 2026
MongoDB Compass can interpolate a database name without escaping into the initial input of its...
High
Unreviewed
CVE-2026-96750
was published
Sep 24, 2026
A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to...
High
Unreviewed
CVE-2026-14780
was published
Sep 24, 2026
OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm definitions, and script suites)
Critical
CVE-2026-77602
was published
for
openc3
(RubyGems)
Sep 23, 2026
orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator...
Critical
Unreviewed
CVE-2026-96754
was published
Sep 23, 2026
orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect...
Critical
Unreviewed
CVE-2026-96755
was published
Sep 23, 2026
orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data...
Critical
Unreviewed
CVE-2026-96758
was published
Sep 23, 2026
orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted...
Critical
Unreviewed
CVE-2026-96757
was published
Sep 23, 2026
orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory...
Critical
Unreviewed
CVE-2026-96756
was published
Sep 23, 2026
orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated...
Critical
Unreviewed
CVE-2026-96759
was published
Sep 23, 2026
webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can...
High
Unreviewed
CVE-2026-79310
was published
Sep 23, 2026
A code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode...
High
Unreviewed
CVE-2026-96442
was published
Sep 23, 2026
The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files...
Critical
Unreviewed
CVE-2026-75799
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to...
Critical
Unreviewed
CVE-2026-18162
was published
Sep 23, 2026
Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability
High
CVE-2026-76819
was published
for
github.com/projectdiscovery/nuclei/v3
(Go)
Sep 22, 2026
MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4)
High
CVE-2026-77271
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code...
Critical
Unreviewed
CVE-2026-89275
was published
Sep 22, 2026
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code...
Critical
Unreviewed
CVE-2026-84412
was published
Sep 22, 2026
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code...
Critical
Unreviewed
CVE-2026-89276
was published
Sep 22, 2026
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code...
Critical
Unreviewed
CVE-2026-75699
was published
Sep 22, 2026
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code...
Critical
Unreviewed
CVE-2026-75721
was published
Sep 22, 2026
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code...
Critical
Unreviewed
CVE-2026-75703
was published
Sep 22, 2026
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code...
Critical
Unreviewed
CVE-2026-73369
was published
Sep 22, 2026
The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in...
High
Unreviewed
CVE-2026-92235
was published
Sep 22, 2026
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and...
Critical
Unreviewed
CVE-2026-94572
was published
Sep 21, 2026
ProTip!
Advisories are also available from the
GraphQL API