GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,569
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,522
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
181 advisories
Filter by severity
Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file...
Moderate
Unreviewed
CVE-2026-34967
was published
Aug 25, 2026
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25...
Moderate
Unreviewed
CVE-2025-36398
was published
Aug 20, 2026
External control of file name or path vulnerability in Citrix WorkSpace App on MacOS.
This issue...
Moderate
Unreviewed
CVE-2026-18751
was published
Aug 18, 2026
uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability
Moderate
CVE-2026-55062
was published
for
gitlab.com/uniget-org/cli
(Go)
Aug 17, 2026
PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the...
Moderate
Unreviewed
CVE-2026-17431
was published
Aug 13, 2026
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or...
Moderate
Unreviewed
CVE-2026-17014
was published
Aug 9, 2026
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
Moderate
GHSA-hh9p-6wh2-4mfc
was published
for
GitPython
(pip)
Aug 7, 2026
A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of...
Moderate
Unreviewed
CVE-2026-19009
was published
Aug 6, 2026
A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function...
Moderate
Unreviewed
CVE-2026-19011
was published
Aug 6, 2026
GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
Moderate
GHSA-539m-9xh6-q6rr
was published
for
GitPython
(pip)
Aug 3, 2026
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a...
Moderate
Unreviewed
CVE-2026-15382
was published
Jul 30, 2026
GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and...
Moderate
Unreviewed
CVE-2026-56390
was published
Jul 29, 2026
proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An...
Moderate
Unreviewed
CVE-2026-57916
was published
Jul 27, 2026
ImageMagick: Policy Bypass in concatenate operation due to missing checks
Moderate
CVE-2026-55628
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore
Moderate
CVE-2026-58420
was published
for
gitea.dev
(Go)
Jul 21, 2026
The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before...
Moderate
Unreviewed
CVE-2026-12979
was published
Jul 16, 2026
External control of file name or path in Microsoft Office SharePoint allows an authorized...
Moderate
Unreviewed
CVE-2026-54108
was published
Jul 14, 2026
psd-tools vulnerable to arbitrary file write via smart-object filename
Moderate
CVE-2026-49836
was published
for
psd-tools
(pip)
Jul 9, 2026
Rattler vulnerable to package cache path traversal via conda package build string
Moderate
CVE-2026-53956
was published
for
py_rattler
(pip)
Jul 9, 2026
oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read)
Moderate
CVE-2026-53508
was published
for
github.com/oasdiff/oasdiff
(Go)
Jul 7, 2026
EGroupware Vulnerable to Local File Inclusion via file:// URI in Mail Compose
Moderate
CVE-2026-45016
was published
for
egroupware/egroupware
(Composer)
Jul 7, 2026
oras-go has file store write outside workingDir via symlink traversal
Moderate
CVE-2026-50162
was published
for
oras.land/oras-go/v2
(Go)
Jul 1, 2026
Keras: HDF5 virtual datasets can disclose local files
Moderate
CVE-2026-12480
was published
for
keras
(pip)
Jul 1, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
Moderate
GHSA-2wwr-9x6f-88gp
was published
for
easycorp/easyadmin-bundle
(Composer)
Jul 1, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM...
Moderate
Unreviewed
CVE-2026-3602
was published
Jun 30, 2026
ProTip!
Advisories are also available from the
GraphQL API