GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
596 advisories
Filter by severity
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint...
High
Unreviewed
CVE-2026-100637
was published
Sep 26, 2026
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon...
High
Unreviewed
CVE-2026-100638
was published
Sep 26, 2026
An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint...
High
Unreviewed
CVE-2026-13248
was published
Sep 24, 2026
Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files
Moderate
CVE-2026-92164
was published
for
streamlink
(pip)
Sep 24, 2026
Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be...
High
Unreviewed
CVE-2026-96656
was published
Sep 23, 2026
Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file...
High
Unreviewed
CVE-2026-91797
was published
Sep 23, 2026
MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters
High
CVE-2026-77247
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause...
Moderate
Unreviewed
CVE-2026-65125
was published
Sep 22, 2026
@roomi-fields/notebooklm-mcp has a path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory
High
CVE-2026-61647
was published
for
@roomi-fields/notebooklm-mcp
(npm)
Sep 22, 2026
MISP has a file-handling vulnerability that could let certain authenticated users make the server...
High
Unreviewed
CVE-2026-94401
was published
Sep 21, 2026
An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough...
Critical
Unreviewed
CVE-2026-90817
was published
Sep 20, 2026
rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve...
Moderate
Unreviewed
CVE-2026-93987
was published
Sep 19, 2026
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not...
Moderate
Unreviewed
CVE-2026-19860
was published
Sep 19, 2026
An external control of file name or path vulnerability in Upload API in Synology DiskStation...
High
Unreviewed
CVE-2026-6205
was published
Sep 18, 2026
Redocly CLI: Path traversal when using `split` command
Moderate
CVE-2026-63225
was published
for
@redocly/cli
(npm)
Sep 17, 2026
Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the ...
Moderate
Unreviewed
CVE-2026-92595
was published
Sep 17, 2026
Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in...
High
Unreviewed
CVE-2026-73171
was published
Sep 16, 2026
The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from...
Moderate
Unreviewed
CVE-2026-76553
was published
Sep 16, 2026
The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service...
Moderate
Unreviewed
CVE-2026-76796
was published
Sep 15, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated...
Critical
Unreviewed
CVE-2026-16338
was published
Sep 14, 2026
DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the...
High
Unreviewed
CVE-2026-90946
was published
Sep 14, 2026
LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core...
High
Unreviewed
CVE-2026-90932
was published
Sep 14, 2026
The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path,...
Critical
Unreviewed
CVE-2026-77006
was published
Sep 12, 2026
The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file...
Critical
Unreviewed
CVE-2026-77005
was published
Sep 12, 2026
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url
High
GHSA-wfgq-w7cq-qj7j
was published
for
mistralrs-server-core
(Rust)
Sep 10, 2026
ProTip!
Advisories are also available from the
GraphQL API