GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
4,539 advisories
Filter by severity
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
Critical
CVE-2026-73080
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 11, 2026
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
Critical
CVE-2026-71851
was published
for
crypto-js
(npm)
Aug 7, 2026
CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules
Critical
CVE-2026-63223
was published
for
codeigniter4/framework
(Composer)
Aug 7, 2026
CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions
Critical
CVE-2026-63221
was published
for
codeigniter4/framework
(Composer)
Aug 7, 2026
Craft CMS: Passkey login accepts replayed WebAuthn assertions
Critical
GHSA-wg23-69c2-gjc8
was published
for
craftcms/cms
(Composer)
Aug 7, 2026
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
Critical
CVE-2026-65600
was published
for
github.com/traefik/traefik
(Go)
Aug 6, 2026
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
Critical
CVE-2026-71319
was published
for
@nuxt/devtools
(npm)
Aug 5, 2026
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
Critical
CVE-2026-70478
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Critical
CVE-2026-70477
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
Critical
CVE-2026-69264
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
Critical
CVE-2026-70470
was published
for
flowise
(npm)
Aug 4, 2026
Flowise RCE via SQLite Record Manager Node
Critical
CVE-2026-69259
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Remote Code Execution Vulnerability in CSVAgent
Critical
CVE-2026-69256
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
Critical
CVE-2026-69255
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
Critical
CVE-2026-69254
was published
for
flowise
(npm)
Aug 4, 2026
Flowise RCE via TypeORM DataSource
Critical
CVE-2026-69251
was published
for
flowise
(npm)
Aug 4, 2026
Sequelize: SQL Injection (Oracle DB)
Critical
CVE-2026-69240
was published
for
sequelize
(npm)
Aug 3, 2026
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
Critical
CVE-2026-53609
was published
for
apostrophe
(npm)
Jul 31, 2026
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
Critical
CVE-2026-52887
was published
for
@nocobase/plugin-notification-in-app-message
(npm)
Jul 31, 2026
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
Critical
CVE-2026-54725
was published
for
github.com/bank-vaults/vault-secrets-webhook
(Go)
Jul 31, 2026
Wings exposes node configuration secrets through egg configuration-file templating
Critical
CVE-2026-52855
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
AWS Amplify Studio UI Component Properties Has an Input Validation Issue
Critical
CVE-2025-4318
was published
for
@aws-amplify/codegen-ui-react
(npm)
Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
CVE-2026-66066
was published
for
activestorage
(RubyGems)
Jul 30, 2026
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
Critical
CVE-2026-67426
was published
for
flyto-core
(pip)
Jul 30, 2026
ProTip!
Advisories are also available from the
GraphQL API