GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
209 advisories
Filter by severity
A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element...
Moderate
Unreviewed
CVE-2026-76572
was published
Aug 19, 2026
A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to...
Moderate
Unreviewed
CVE-2026-68562
was published
Jul 31, 2026
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
High
CVE-2026-55389
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
High
CVE-2026-55390
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to...
High
Unreviewed
CVE-2026-15583
was published
Jul 15, 2026
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to...
High
Unreviewed
CVE-2026-10816
was published
Jun 30, 2026
Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller...
High
Unreviewed
CVE-2026-57301
was published
Jun 24, 2026
Apache Camel K: Kubernetes namespace authorized users can create a Build resource
High
CVE-2026-45760
was published
for
github.com/apache/camel-k/v2
(Go)
May 21, 2026
A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform...
Low
Unreviewed
CVE-2026-12788
was published
Jun 21, 2026
External control of file name or path in SQL Server allows an authorized attacker to execute code...
High
Unreviewed
CVE-2026-40370
was published
May 12, 2026
External control of file name or path in Azure Monitor Agent allows an authorized attacker to...
High
Unreviewed
CVE-2026-32204
was published
May 12, 2026
Insufficient configuration management in the listed devices allows authenticated administrators...
Moderate
Unreviewed
CVE-2026-0418
was published
Jun 9, 2026
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to...
Critical
Unreviewed
CVE-2026-47643
was published
Jun 9, 2026
Confused Deputy in Kubernetes
Moderate
CVE-2020-8561
was published
for
k8s.io/kubernetes
(Go)
Sep 21, 2021
Confused Deputy in Kubernetes
Low
CVE-2021-25740
was published
for
k8s.io/kubernetes
(Go)
Sep 21, 2021
External Control of File Name or Path in Langflow
High
CVE-2025-68478
was published
for
langflow
(pip)
Dec 19, 2025
External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal...
High
Unreviewed
CVE-2026-30905
was published
May 13, 2026
OpenClaw: Workspace dotenv files cannot override connector endpoint hosts
Moderate
CVE-2026-45003
was published
for
openclaw
(npm)
May 4, 2026
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized...
High
Unreviewed
CVE-2026-41107
was published
May 12, 2026
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6...
Critical
Unreviewed
CVE-2026-30903
was published
Mar 11, 2026
Externally controlled reference to a resource in another sphere in Microsoft Partner Center...
High
Unreviewed
CVE-2026-34327
was published
May 8, 2026
An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows...
Moderate
Unreviewed
CVE-2026-30817
was published
Apr 8, 2026
An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0...
Moderate
Unreviewed
CVE-2026-30816
was published
Apr 8, 2026
External Control of File Name or Path in h2oai/h2o-3
Critical
CVE-2023-6569
was published
for
h2o
(pip)
Dec 14, 2023
The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary...
Moderate
Unreviewed
CVE-2022-2943
was published
Sep 7, 2022
ProTip!
Advisories are also available from the
GraphQL API