GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,569
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,522
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
240 advisories
Filter by severity
GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create()...
High
Unreviewed
CVE-2026-78679
was published
Aug 25, 2026
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
High
Unreviewed
CVE-2026-78675
was published
Aug 25, 2026
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
High
CVE-2026-55477
was published
for
github.com/mhsanaei/3x-ui/v2
(Go)
Aug 24, 2026
exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage()...
High
Unreviewed
CVE-2026-78208
was published
Aug 24, 2026
NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and...
High
Unreviewed
CVE-2026-62385
was published
Aug 22, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation
High
CVE-2026-64679
was published
for
github.com/runatlantis/atlantis
(Go)
Aug 21, 2026
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
High
GHSA-ghvf-qf6h-g8x5
was published
for
@nocobase/server
(npm)
Aug 20, 2026
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
High
GHSA-rr55-jp92-8wp2
was published
for
claude-faf-mcp
(npm)
Aug 19, 2026
faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
High
GHSA-j4r7-8ph4-43g3
was published
for
faf-mcp
(npm)
Aug 19, 2026
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
High
GHSA-cc2g-gq8c-r332
was published
for
grok-faf-mcp
(npm)
Aug 19, 2026
GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout...
High
Unreviewed
CVE-2026-76217
was published
Aug 19, 2026
phpMyFAQ before 4.1.7 does not adequately sanitize HTML in FAQ answers before generating PDFs via...
High
Unreviewed
CVE-2026-76210
was published
Aug 19, 2026
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app...
High
Unreviewed
CVE-2026-67920
was published
Aug 18, 2026
grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path...
High
Unreviewed
CVE-2026-75830
was published
Aug 18, 2026
openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path...
High
Unreviewed
CVE-2026-74884
was published
Aug 17, 2026
External control of file name or path vulnerability in Johnson Controls Airwall allows : File...
High
Unreviewed
CVE-2026-34492
was published
Aug 14, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to...
High
Unreviewed
CVE-2026-16987
was published
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership...
High
Unreviewed
CVE-2026-16898
was published
Aug 13, 2026
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard...
High
Unreviewed
CVE-2026-73619
was published
Aug 13, 2026
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with...
High
Unreviewed
CVE-2026-65941
was published
Aug 12, 2026
SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
High
CVE-2026-48798
was published
for
SSH.NET
(NuGet)
Aug 12, 2026
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled...
High
Unreviewed
CVE-2026-18048
was published
Aug 12, 2026
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7...
High
Unreviewed
CVE-2026-18127
was published
Aug 11, 2026
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
High
GHSA-hmq2-w58f-27jc
was published
for
GitPython
(pip)
Aug 7, 2026
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability...
High
Unreviewed
CVE-2026-54200
was published
Aug 7, 2026
ProTip!
Advisories are also available from the
GraphQL API