GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,912
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
48 advisories
Filter by severity
Payload authentication token field handling issue
Critical
CVE-2026-105863
was published
for
payload
(npm)
Oct 7, 2026
SPIP before 4.4.18 contains a remote code execution vulnerability in the editer_objet action...
Critical
Unreviewed
CVE-2026-72710
was published
Sep 11, 2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in...
Critical
Unreviewed
CVE-2026-55810
was published
Jul 11, 2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in...
Critical
Unreviewed
CVE-2026-55809
was published
Jul 11, 2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in...
Critical
Unreviewed
CVE-2026-12535
was published
Jul 11, 2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in...
Critical
Unreviewed
CVE-2026-9726
was published
Jul 10, 2026
In JetBrains Hub before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,...
Critical
Unreviewed
CVE-2026-56142
was published
Jun 19, 2026
Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
Critical
CVE-2026-48150
was published
for
@budibase/server
(npm)
Jun 12, 2026
Electerm: Importing unsafe bookmark data could lead to unsafe operation when clicking local type bookmark
Critical
CVE-2026-45058
was published
for
electerm
(npm)
May 14, 2026
Apache camel-coap allows header injection that can lead to remote code execution
Critical
CVE-2026-33453
was published
for
org.apache.camel:camel-coap
(Maven)
Apr 27, 2026
LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin
Critical
CVE-2026-34179
was published
for
github.com/canonical/lxd
(Go)
Apr 10, 2026
SandboxJS: Sandbox integrity escape
Critical
CVE-2026-34208
was published
for
@nyariv/sandboxjs
(npm)
Apr 3, 2026
Winter vulnerable to privilege escalation by authenticated backend users
Critical
CVE-2026-27591
was published
for
winter/wn-backend-module
(Composer)
Mar 12, 2026
locutus is vulnerable to Prototype Pollution
Critical
CVE-2026-25521
was published
for
locutus
(npm)
Feb 2, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
Critical
CVE-2025-68924
was published
for
UmbracoForms
(NuGet)
Jan 13, 2026
DeepDiff Class Pollution in Delta class leading to DoS, Remote Code Execution, and more
Critical
CVE-2025-58367
was published
for
deepdiff
(pip)
Sep 3, 2025
Camaleon CMS Vulnerable to Privilege Escalation through a Mass Assignment
Critical
CVE-2025-2304
was published
for
camaleon_cms
(RubyGems)
Mar 14, 2025
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
CVE-2025-24370
was published
for
django-unicorn
(pip)
Feb 3, 2025
Apache Struts file upload logic is flawed
Critical
CVE-2024-53677
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 11, 2024
Remote code execution in pytorch lightning
Critical
CVE-2024-5452
was published
for
lightning
(pip)
Jun 6, 2024
A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs...
Critical
Unreviewed
CVE-2024-0404
was published
Apr 16, 2024
qcubed PHP object injection
Critical
CVE-2020-24914
was published
for
qcubed/qcubed
(Composer)
May 24, 2022
Prototype polluation in just-safe-set
Critical
CVE-2021-25952
was published
for
just-safe-set
(npm)
Dec 10, 2021
Improperly Controlled Modification of Dynamically-Determined Object Attributes in Apache Struts
Critical
CVE-2019-0230
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 2, 2021
ProTip!
Advisories are also available from the
GraphQL API