GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
12,303 advisories
Filter by severity
Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
High
CVE-2026-55157
was published
for
@ooples/token-optimizer-mcp
(npm)
Aug 14, 2026
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
High
CVE-2026-55153
was published
for
com.mchange:mchange-commons-java
(Maven)
Aug 14, 2026
OpenAM Insecure SSO Cookie Initialization
High
CVE-2026-53660
was published
for
org.openidentityplatform.openam:openam-core
(Maven)
Aug 14, 2026
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
High
CVE-2026-53657
was published
for
github.com/lima-vm/lima/v2
(Go)
Aug 14, 2026
Grav: Unauthenticated denial of service via unbounded image derivative dimensions
High
CVE-2026-53653
was published
for
getgrav/grav
(Composer)
Aug 14, 2026
Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
High
CVE-2026-35219
was published
for
@budibase/server
(npm)
Aug 14, 2026
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
High
CVE-2026-35511
was published
for
github.com/authorizerdev/authorizer
(Go)
Aug 14, 2026
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
High
CVE-2026-73654
was published
for
@trigger.dev/core
(npm)
Aug 13, 2026
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
High
CVE-2026-12243
was published
for
nltk
(pip)
Aug 13, 2026
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
High
GHSA-rm43-82j9-r4mj
was published
for
atomic-agents-stack
(pip)
Aug 13, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
High
CVE-2026-54526
was published
for
github.com/argoproj/argo-workflows
(Go)
Aug 13, 2026
Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name
High
CVE-2026-55072
was published
for
pimcore/pimcore
(Composer)
Aug 13, 2026
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
High
CVE-2026-55074
was published
for
ansible-jailexec
(pip)
Aug 12, 2026
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
High
GHSA-pfvm-w89x-94jw
was published
for
SIPSorcery
(NuGet)
Aug 12, 2026
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
High
GHSA-jwjp-4649-v8jp
was published
for
SIPSorcery
(NuGet)
Aug 12, 2026
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
High
CVE-2026-55071
was published
for
stata-mcp
(pip)
Aug 12, 2026
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
High
CVE-2026-54917
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 12, 2026
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
High
CVE-2026-52776
was published
for
compliance-trestle
(pip)
Aug 12, 2026
SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
High
CVE-2026-48798
was published
for
SSH.NET
(NuGet)
Aug 12, 2026
nimiq-blockchain: Validity store off by one error
High
CVE-2026-46369
was published
for
nimiq-blockchain
(Rust)
Aug 12, 2026
Winter: Authenticated backend users can bypass Users controller permission checks
High
CVE-2026-35445
was published
for
winter/wn-backend-module
(Composer)
Aug 12, 2026
Winter: Stored XSS through Editor Settings custom styles
High
CVE-2026-32258
was published
for
winter/wn-backend-module
(Composer)
Aug 12, 2026
Winter: Stored XSS through Brand Settings custom styles
High
CVE-2026-32257
was published
for
winter/wn-backend-module
(Composer)
Aug 12, 2026
Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability
High
CVE-2026-62871
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-arm64
(NuGet)
Aug 11, 2026
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability
High
CVE-2026-62897
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-arm64
(NuGet)
Aug 11, 2026
ProTip!
Advisories are also available from the
GraphQL API