GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
36,003 advisories
Filter by severity
SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests
High
CVE-2026-57443
was published
for
scbe-aethermoore
(pip)
Sep 25, 2026
mpp vulnerable to Gas Draining with low gas limit
High
GHSA-vj8p-hp9x-gh47
was published
for
mpp
(Erlang)
Sep 25, 2026
mpp vulnerable to Gas Draining with access list
Moderate
GHSA-qpxh-ff8m-c62v
was published
for
mpp
(Erlang)
Sep 25, 2026
mpp vulnerable to Gas Draining with no limit
High
GHSA-vv77-66rf-pm86
was published
for
mpp
(Erlang)
Sep 25, 2026
CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers
High
CVE-2026-100368
was published
for
AlastairLundy.CliInvoke.Specializations
(NuGet)
Sep 25, 2026
CliInvoke: Argument Injection in Extensibility Runner Factory
High
CVE-2026-100369
was published
for
AlastairLundy.CliInvoke
(NuGet)
Sep 25, 2026
khoj has an unauthenticated path traversal in /home/ endpoint that allows file read from server filesystem
High
GHSA-62mm-xwmv-crhg
was published
for
khoj
(pip)
Sep 25, 2026
Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary .md file read, write, and deletion in MCP Docs + Memory Tools
High
CVE-2026-86439
was published
for
knowns
(npm)
Sep 25, 2026
OpenZeppelin Confidential Contracts `VestingWalletConfidential`: a malicious ERC-7984 token is able to extract private data from the vesting wallet
High
GHSA-29h2-jr22-frmh
was published
for
@openzeppelin/confidential-contracts
(npm)
Sep 25, 2026
Containerd has image-pull DoS via crafted OCI index graph amplification
Moderate
CVE-2026-53493
was published
for
github.com/containerd/containerd
(Go)
Sep 25, 2026
FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider
Critical
CVE-2026-92161
was published
for
fof/oauth
(Composer)
Sep 25, 2026
Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled
High
CVE-2026-57440
was published
for
starcitizenwiki/embedvideo
(Composer)
Sep 25, 2026
code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute
High
CVE-2026-61823
was published
for
code16/sharp
(Composer)
Sep 25, 2026
code16/sharp has a stored XSS via data-html-content Sanitizer Bypass
High
CVE-2026-61825
was published
for
code16/sharp
(Composer)
Sep 25, 2026
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module
Low
CVE-2026-57232
was published
for
contao/contao
(Composer)
Sep 24, 2026
social-auth-core has a Session Fixation issue
Moderate
CVE-2026-57179
was published
for
social-auth-core
(pip)
Sep 24, 2026
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing
High
CVE-2026-57178
was published
for
social-auth-core
(pip)
Sep 24, 2026
social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend
Moderate
CVE-2026-57177
was published
for
social-auth-core
(pip)
Sep 24, 2026
social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend
Moderate
CVE-2026-57176
was published
for
social-auth-core
(pip)
Sep 24, 2026
social-auth-core has an Improper Authentication issue
Moderate
CVE-2026-57175
was published
for
social-auth-core
(pip)
Sep 24, 2026
Ash: Private action arguments can be set by user input via string-keyed params and atomic changesets
Moderate
CVE-2026-55736
was published
for
ash
(Erlang)
Sep 24, 2026
Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)
High
CVE-2026-57171
was published
for
compliance-trestle
(pip)
Sep 24, 2026
Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)
High
CVE-2026-57170
was published
for
compliance-trestle
(pip)
Sep 24, 2026
Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)
High
CVE-2026-59723
was published
for
cline
(npm)
Sep 24, 2026
zbateson/mail-mime-parser has CRLF header injection via attachment filename
High
CVE-2026-61815
was published
for
zbateson/mail-mime-parser
(Composer)
Sep 24, 2026
ProTip!
Advisories are also available from the
GraphQL API