GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
451 advisories
Filter by severity
FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`
Low
CVE-2026-45710
was published
for
facturascripts/facturascripts
(Composer)
Jul 14, 2026
luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first...
High
Unreviewed
CVE-2026-62184
was published
Jul 14, 2026
Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization
Moderate
CVE-2026-49844
was published
for
org.apache.logging.log4j:log4j-api
(Maven)
Jul 11, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
CVE-2026-48598
was published
for
tesla
(Erlang)
Jul 10, 2026
YesWiki has stored XSS in Bazar form-field templates via unescaped field.label / field.hint (|raw('html'))
Moderate
CVE-2026-52772
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path
Low
GHSA-cwv4-h3j5-w3cf
was published
for
rama
(Rust)
Jul 7, 2026
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)
Moderate
CVE-2026-35366
was published
for
uu_printenv
(Rust)
Jul 6, 2026
comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output
Low
CVE-2026-35346
was published
for
uu_comm
(Rust)
Jul 6, 2026
Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log...
High
Unreviewed
CVE-2026-49091
was published
Jul 1, 2026
justhtml: to_markdown() code-span blank-line breakout enables XSS
Moderate
GHSA-jf6w-2mvx-633j
was published
for
justhtml
(pip)
Jun 25, 2026
An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic...
Low
Unreviewed
CVE-2026-40011
was published
Jun 25, 2026
Duplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
Low
GHSA-v772-658q-978p
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 23, 2026
•
withdrawn
Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
Moderate
CVE-2026-44913
was published
for
org.apache.nifi:nifi-cdc-mysql-processors
(Maven)
Jun 22, 2026
OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source
Low
GHSA-9wxg-vf3r-56hc
was published
for
@openzeppelin/wizard
(npm)
Jun 19, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers
High
CVE-2026-57210
was published
for
https://github.com/dadrus/heimdall
(Go)
Jun 18, 2026
Open WebUI: Stored XSS to Account Takeover via Model Profile Images
High
CVE-2026-54013
was published
for
open-webui
(pip)
Jun 17, 2026
Laravel Framework: Temporary Signed URL Path Confusion
Moderate
GHSA-crmm-hgp2-wgrp
was published
for
laravel/framework
(Composer)
Jun 17, 2026
Caddy: stripHTML template function bypass
Moderate
CVE-2026-52846
was published
for
github.com/caddyserver/caddy
(Go)
Jun 16, 2026
hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
Moderate
CVE-2026-54287
was published
for
hono
(npm)
Jun 16, 2026
Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
Moderate
CVE-2026-44311
was published
for
fabric
(npm)
Jun 12, 2026
SwiftNIO HTTP/2: HTTP/2-to-HTTP/1 Request Smuggling via unvalidated :path pseudo-header in HTTP2ToHTTP1Codec
Moderate
CVE-2026-28898
was published
for
github.com/apple/swift-nio-http2
(Swift)
Jun 12, 2026
Firefly II has Stored XSS in Audit Log Entry view via piggy bank name (ale.twig)
Moderate
GHSA-6jq6-x4cx-qvcm
was published
for
grumpydictator/firefly-iii
(Composer)
Jun 12, 2026
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)
Moderate
CVE-2026-47768
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 10, 2026
A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow...
High
Unreviewed
CVE-2026-20245
was published
Jun 5, 2026
CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters
Moderate
CVE-2026-44587
was published
for
carrierwave
(RubyGems)
May 27, 2026
ProTip!
Advisories are also available from the
GraphQL API