GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,569
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,522
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
515 advisories
Filter by severity
The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary...
High
Unreviewed
CVE-2026-8095
was published
Jun 28, 2026
pnpm: `patch-remove` could delete project-selected files outside the patches directory
High
GHSA-72r4-9c5j-mj57
was published
for
pnpm
(npm)
Jun 27, 2026
pnpm: Hoisted install imports lockfile alias outside node_modules
High
GHSA-fr4h-3cph-29xv
was published
for
pnpm
(npm)
Jun 27, 2026
pnpm: `stage download` writes outside its destination directory via manifest name/version traversal
High
CVE-2026-55700
was published
for
pnpm
(npm)
Jun 26, 2026
pnpm: Reserved bin name deletes PNPM_HOME during global remove
Moderate
CVE-2026-55699
was published
for
pnpm
(npm)
Jun 26, 2026
PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles
Low
CVE-2026-49358
was published
for
pontedilana/php-weasyprint
(Composer)
Jun 26, 2026
Incus has an arbitrary file write via path traversal in S3 multipart upload
Critical
CVE-2026-48753
was published
for
github.com/lxc/incus/v7/cmd/incusd
(Go)
Jun 26, 2026
Incus has arbitrary file read+write on host via templates/ symlink in malicious image
Critical
CVE-2026-48752
was published
for
github.com/lxc/incus/v7/cmd/incusd
(Go)
Jun 26, 2026
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image
Critical
CVE-2026-48750
was published
for
github.com/lxc/incus/v7/cmd/incusd
(Go)
Jun 26, 2026
Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image
Critical
CVE-2026-48749
was published
for
github.com/lxc/incus/v7/cmd/incusd
(Go)
Jun 26, 2026
Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access...
Critical
Unreviewed
CVE-2025-71334
was published
Jun 26, 2026
Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process...
Critical
Unreviewed
CVE-2025-71338
was published
Jun 26, 2026
Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the...
High
Unreviewed
CVE-2025-71324
was published
Jun 26, 2026
Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api...
Critical
Unreviewed
CVE-2025-71333
was published
Jun 26, 2026
OctoPrint has possible file exfiltration via query parameters on upload endpoints
High
CVE-2026-54134
was published
for
OctoPrint
(pip)
Jun 23, 2026
Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
High
GHSA-2fmp-9rvw-hc96
was published
for
network-ai
(npm)
Jun 19, 2026
In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project...
High
Unreviewed
CVE-2026-53915
was published
Jun 19, 2026
Entire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewind
Moderate
GHSA-2h46-9x5w-4wf7
was published
for
github.com/entireio/cli
(Go)
Jun 19, 2026
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-8118
was published
Jun 19, 2026
Armeria: External Control of File Name or Path in xDS SDS DataSource
Moderate
CVE-2026-11752
was published
for
com.linecorp.armeria:armeria-xds
(Maven)
Jun 18, 2026
BBOT: Arbitrary File Write in postman_download Module
Moderate
CVE-2026-12568
was published
for
bbot
(pip)
Jun 18, 2026
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
High
GHSA-p6gq-j5cr-w38f
was published
for
nodemailer
(npm)
Jun 18, 2026
PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
High
CVE-2026-57113
was published
for
praisonai
(pip)
Jun 18, 2026
A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file...
Moderate
Unreviewed
CVE-2026-2604
was published
Jun 17, 2026
In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was...
High
Unreviewed
CVE-2026-10303
was published
Jun 16, 2026
ProTip!
Advisories are also available from the
GraphQL API