GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,575
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,522
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
181 advisories
Filter by severity
Rattler vulnerable to package cache path traversal via conda package build string
Moderate
CVE-2026-53956
was published
for
py_rattler
(pip)
Jul 9, 2026
oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read)
Moderate
CVE-2026-53508
was published
for
github.com/oasdiff/oasdiff
(Go)
Jul 7, 2026
EGroupware Vulnerable to Local File Inclusion via file:// URI in Mail Compose
Moderate
CVE-2026-45016
was published
for
egroupware/egroupware
(Composer)
Jul 7, 2026
oras-go has file store write outside workingDir via symlink traversal
Moderate
CVE-2026-50162
was published
for
oras.land/oras-go/v2
(Go)
Jul 1, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
Moderate
GHSA-2wwr-9x6f-88gp
was published
for
easycorp/easyadmin-bundle
(Composer)
Jul 1, 2026
pnpm: Reserved bin name deletes PNPM_HOME during global remove
Moderate
CVE-2026-55699
was published
for
pnpm
(npm)
Jun 26, 2026
Entire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewind
Moderate
GHSA-2h46-9x5w-4wf7
was published
for
github.com/entireio/cli
(Go)
Jun 19, 2026
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-8118
was published
Jun 19, 2026
BBOT: Arbitrary File Write in postman_download Module
Moderate
CVE-2026-12568
was published
for
bbot
(pip)
Jun 18, 2026
A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file...
Moderate
Unreviewed
CVE-2026-2604
was published
Jun 17, 2026
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
Moderate
CVE-2026-53632
was published
for
launch-editor
(npm)
Jun 15, 2026
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, does not sufficiently...
Moderate
Unreviewed
CVE-2026-34030
was published
Jun 15, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Moderate
CVE-2026-47425
was published
for
py-rattler
(pip)
Jun 1, 2026
Streamlink has an arbitrary local file read via file:// URI in HLS and DASH
Moderate
CVE-2026-44353
was published
for
streamlink
(pip)
May 11, 2026
A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load...
Moderate
Unreviewed
CVE-2026-20175
was published
Jun 3, 2026
A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this...
Moderate
Unreviewed
CVE-2026-10694
was published
Jun 3, 2026
The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in...
Moderate
Unreviewed
CVE-2025-0898
was published
May 27, 2026
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
Moderate
CVE-2026-45139
was published
for
ci4-cms-erp/ci4ms
(Composer)
May 18, 2026
Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
Moderate
CVE-2026-46383
was published
for
apm-cli
(pip)
May 15, 2026
Gotenberg has arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes
Moderate
CVE-2026-42593
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 7, 2026
External control of file name or path in Microsoft Office Word allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2026-40421
was published
May 12, 2026
OpenClaw: Webchat media embedding enforces local-root containment for tool-result files
Moderate
CVE-2026-41389
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Shared reply MEDIA - paths are treated as trusted and can trigger cross-channel local file exfiltration
Moderate
CVE-2026-42424
was published
for
openclaw
(npm)
Apr 9, 2026
Duplicate Advisory: OpenClaw: Webchat media embedding enforces local-root containment for tool-result files
Moderate
GHSA-qc5j-2mqx-x83q
was published
for
openclaw
(npm)
Apr 20, 2026
•
withdrawn
A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function...
Moderate
Unreviewed
CVE-2026-7633
was published
May 2, 2026
ProTip!
Advisories are also available from the
GraphQL API