GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
9,573 advisories
Filter by severity
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and...
Critical
Unreviewed
CVE-2026-81939
was published
Sep 4, 2026
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain...
Moderate
Unreviewed
CVE-2026-17622
was published
Sep 4, 2026
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on...
Moderate
Unreviewed
CVE-2026-17621
was published
Sep 4, 2026
IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse...
Moderate
Unreviewed
CVE-2026-14470
was published
Sep 4, 2026
IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files...
High
Unreviewed
CVE-2026-19306
was published
Sep 4, 2026
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete...
High
Unreviewed
CVE-2026-19303
was published
Sep 4, 2026
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain...
Moderate
Unreviewed
CVE-2026-19302
was published
Sep 4, 2026
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain...
Moderate
Unreviewed
CVE-2026-19299
was published
Sep 4, 2026
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
High
CVE-2026-75859
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
High
CVE-2026-75914
was published
for
codewhale
(npm)
Sep 4, 2026
IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write...
Moderate
Unreviewed
CVE-2026-9138
was published
Sep 4, 2026
Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows...
High
Unreviewed
CVE-2026-85690
was published
Sep 4, 2026
AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace...
High
Unreviewed
CVE-2026-85685
was published
Sep 4, 2026
Bruno versions through 3.4.2 fail to validate file paths in request body declarations, allowing...
High
Unreviewed
CVE-2026-85665
was published
Sep 4, 2026
excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is...
Critical
Unreviewed
CVE-2026-85661
was published
Sep 4, 2026
ConvertX 0.17.0 contains an arbitrary file read vulnerability in the xelatex converter that...
High
Unreviewed
CVE-2026-85618
was published
Sep 4, 2026
firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the...
High
Unreviewed
CVE-2026-85606
was published
Sep 4, 2026
GFI Exinda AI before 7.6.5 contains a path traversal vulnerability in the diagnostic file...
High
Unreviewed
CVE-2026-74236
was published
Sep 4, 2026
GFI Exinda AI before 7.6.5 contains a path traversal vulnerability in the system maintenance...
Moderate
Unreviewed
CVE-2026-74235
was published
Sep 4, 2026
SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access...
High
Unreviewed
CVE-2026-85580
was published
Sep 4, 2026
A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK...
High
Unreviewed
CVE-2026-79707
was published
Sep 4, 2026
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a...
Moderate
Unreviewed
CVE-2026-82193
was published
Sep 4, 2026
A vulnerability was identified in Eleveo Quality Management 9.7.0. The affected element is the...
Low
Unreviewed
CVE-2026-85409
was published
Sep 4, 2026
MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in...
Moderate
Unreviewed
CVE-2026-85456
was published
Sep 4, 2026
Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to...
High
Unreviewed
CVE-2026-67397
was published
Sep 4, 2026
ProTip!
Advisories are also available from the
GraphQL API