GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
451 advisories
Filter by severity
Contao: Cross-site scripting in the comments bundle
Critical
CVE-2026-107845
was published
for
contao/comments-bundle
(Composer)
Oct 9, 2026
PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
High
CVE-2026-61433
was published
for
praisonai
(pip)
Oct 8, 2026
Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates
Moderate
CVE-2026-106444
was published
for
handlebars
(npm)
Oct 8, 2026
PraisonAI: Prompt Injection Defense Bypassed for HIGH-Level Threats
High
CVE-2026-61439
was published
for
PraisonAI
(pip)
Oct 7, 2026
Quasar Framework: App Vite SSR and SSG nonce attributes are not safely constrained
High
CVE-2026-106107
was published
for
@quasar/app-vite
(npm)
Oct 7, 2026
Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering in getHead()
Critical
CVE-2026-106102
was published
for
quasar
(npm)
Oct 7, 2026
Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache...
Moderate
Unreviewed
CVE-2026-105244
was published
Oct 6, 2026
openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation
High
CVE-2026-105801
was published
for
openapi-python-client
(pip)
Oct 6, 2026
@vue/server-renderer: XSS via missing CR in attribute-name blacklist
High
GHSA-g2v6-rqmx-r4w6
was published
for
@vue/server-renderer
(npm)
Oct 5, 2026
Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF
Critical
GHSA-jqmf-mx4f-hfr6
was published
for
vibe-trading-ai
(pip)
Oct 2, 2026
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a...
Moderate
Unreviewed
CVE-2026-47562
was published
Sep 30, 2026
Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote...
High
Unreviewed
CVE-2026-95274
was published
Sep 29, 2026
fast-uri vulnerable to authority injection via an unvalidated port in serialize
High
CVE-2026-84292
was published
for
fast-uri
(npm)
Sep 28, 2026
Angular SSR: XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content Elements
High
CVE-2026-88058
was published
for
@angular/platform-server
(npm)
Sep 28, 2026
xhtml-purifier has HTML attribute-injection (sanitizer bypass) that leads to XSS
Moderate
CVE-2026-61784
was published
for
xhtml-purifier
(npm)
Sep 24, 2026
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery
High
CVE-2026-82409
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager ...
Critical
Unreviewed
CVE-2026-13684
was published
Sep 18, 2026
An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation...
Moderate
Unreviewed
CVE-2026-13635
was published
Sep 18, 2026
djust: A template binding inherits a context safety grant it never earned (XSS)
High
GHSA-xjw9-38cr-6372
was published
for
djust
(pip)
Sep 17, 2026
djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)
High
GHSA-9395-2g46-rj3f
was published
for
djust
(pip)
Sep 17, 2026
RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection
High
CVE-2026-77404
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape...
Moderate
Unreviewed
CVE-2026-13407
was published
Sep 16, 2026
On affected platforms running Arista EOS with password authentication configured, a specially...
Moderate
Unreviewed
CVE-2026-19641
was published
Sep 15, 2026
Improper Encoding or Escaping of Output vulnerability in Apache Syncope.
Authenticated users...
High
Unreviewed
CVE-2026-73195
was published
Sep 14, 2026
Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements
High
CVE-2026-88060
was published
for
@angular/platform-server
(npm)
Sep 10, 2026
ProTip!
Advisories are also available from the
GraphQL API