GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
596 advisories
Filter by severity
External control of file name or path vulnerability in Citrix WorkSpace App on MacOS.
This issue...
Moderate
Unreviewed
CVE-2026-18751
was published
Aug 18, 2026
grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path...
High
Unreviewed
CVE-2026-75830
was published
Aug 18, 2026
uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability
Moderate
CVE-2026-55062
was published
for
gitlab.com/uniget-org/cli
(Go)
Aug 17, 2026
openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path...
High
Unreviewed
CVE-2026-74884
was published
Aug 17, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code...
Critical
Unreviewed
CVE-2026-17184
was published
Aug 14, 2026
External control of file name or path vulnerability in Johnson Controls Airwall allows : File...
High
Unreviewed
CVE-2026-34492
was published
Aug 14, 2026
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated...
Critical
Unreviewed
CVE-2026-72842
was published
Aug 14, 2026
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload,...
Critical
Unreviewed
CVE-2026-72841
was published
Aug 14, 2026
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2026-17482
was published
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to...
High
Unreviewed
CVE-2026-16987
was published
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership...
High
Unreviewed
CVE-2026-16898
was published
Aug 13, 2026
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard...
High
Unreviewed
CVE-2026-73619
was published
Aug 13, 2026
PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the...
Moderate
Unreviewed
CVE-2026-17431
was published
Aug 13, 2026
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with...
High
Unreviewed
CVE-2026-65941
was published
Aug 12, 2026
SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
High
CVE-2026-48798
was published
for
SSH.NET
(NuGet)
Aug 12, 2026
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled...
High
Unreviewed
CVE-2026-18048
was published
Aug 12, 2026
DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field...
Critical
Unreviewed
CVE-2026-72742
was published
Aug 11, 2026
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7...
High
Unreviewed
CVE-2026-18127
was published
Aug 11, 2026
A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the...
Low
Unreviewed
CVE-2026-19353
was published
Aug 9, 2026
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or...
Moderate
Unreviewed
CVE-2026-17014
was published
Aug 9, 2026
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
High
CVE-2026-76222
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
Moderate
CVE-2026-76217
was published
for
GitPython
(pip)
Aug 7, 2026
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability...
High
Unreviewed
CVE-2026-54200
was published
Aug 7, 2026
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion ...
High
Unreviewed
CVE-2026-12070
was published
Aug 7, 2026
A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of...
Moderate
Unreviewed
CVE-2026-19009
was published
Aug 6, 2026
ProTip!
Advisories are also available from the
GraphQL API