GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,627
Maven
5,000+
npm
5,000+
NuGet
928
pip
4,848
Pub
13
RubyGems
1,045
Rust
1,301
Swift
53
Unreviewed advisories
All unreviewed
5,000+
329,507 advisories
Filter by severity
i18next-locize-backend has URL Injection via Unsanitized Path Parameters
Moderate
CVE-2026-41885
was published
for
i18next-locize-backend
(npm)
Apr 22, 2026
OmniFaces: EL injection via crafted resource name in wildcard CDN mapping
High
CVE-2026-41883
was published
for
org.omnifaces:omnifaces
(Maven)
Apr 16, 2026
i18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwrite
High
CVE-2026-41693
was published
for
i18next-fs-backend
(npm)
Apr 22, 2026
i18nextify has DOM XSS via javascript:/data: URL schemes in translated href/src attributes
Moderate
CVE-2026-41692
was published
for
i18nextify
(npm)
Apr 22, 2026
i18next-http-backend has Path Traversal & URL Injection via Unsanitised lng/ns
Moderate
CVE-2026-41691
was published
for
i18next-http-backend
(npm)
Apr 22, 2026
i18next-http-middleware: Prototype pollution and path traversal via user-controlled language and namespace parameters
High
CVE-2026-41690
was published
for
i18next-http-middleware
(npm)
Apr 22, 2026
Pillow affected by out-of-bounds write when loading PSD images
High
CVE-2026-25990
was published
for
pillow
(pip)
Feb 11, 2026
Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS
High
CVE-2026-35569
was published
for
apostrophe
(npm)
Apr 16, 2026
Inspektor Gadget: Command Injection via malicious buildOptions manipulation
Moderate
CVE-2026-24905
was published
for
github.com/inspektor-gadget/inspektor-gadget
(Go)
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
Moderate
CVE-2026-41201
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 22, 2026
AgentScope Vulnerable to Remote Code Injection
Moderate
CVE-2026-6603
was published
for
agentscope
(pip)
Apr 20, 2026
OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter
Moderate
CVE-2026-42191
was published
for
OpenTelemetry.Exporter.OpenTelemetryProtocol
(NuGet)
Apr 30, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
Critical
CVE-2026-35035
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 6, 2026
Withdrawn Advisory: Kirby CMS has Persistent DoS via Malformed Image Upload
Moderate
CVE-2026-29905
was published
for
getkirby/cms
(Composer)
Mar 27, 2026
•
withdrawn
Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions...
Critical
Unreviewed
CVE-2025-60889
was published
Apr 28, 2026
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially...
Moderate
Unreviewed
CVE-2026-6732
was published
Apr 24, 2026
Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus...
Moderate
Unreviewed
CVE-2026-40557
was published
Apr 27, 2026
Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This...
Critical
Unreviewed
CVE-2026-7321
was published
Apr 28, 2026
Memory safety bugs present in Firefox 150.0.0 and Thunderbird 150.0.0. Some of these bugs showed...
High
Unreviewed
CVE-2026-7324
was published
Apr 28, 2026
Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to...
Moderate
Unreviewed
CVE-2026-38940
was published
Apr 30, 2026
An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary...
High
Unreviewed
CVE-2026-36340
was published
Apr 30, 2026
An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4...
Unknown
Unreviewed
CVE-2026-36765
was published
Apr 30, 2026
A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint...
Moderate
Unreviewed
CVE-2026-36763
was published
Apr 30, 2026
Synway SMG Gateway Management Software contains an OS command injection vulnerability in the...
Critical
Unreviewed
CVE-2025-71284
was published
Apr 30, 2026
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a...
Low
Unreviewed
CVE-2026-3832
was published
Apr 30, 2026
ProTip!
Advisories are also available from the
GraphQL API