GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
208 advisories
Filter by severity
A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to...
Moderate
Unreviewed
CVE-2026-68562
was published
Jul 31, 2026
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
High
CVE-2026-55389
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
High
CVE-2026-55390
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to...
High
Unreviewed
CVE-2026-15583
was published
Jul 15, 2026
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to...
High
Unreviewed
CVE-2026-10816
was published
Jun 30, 2026
Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller...
High
Unreviewed
CVE-2026-57301
was published
Jun 24, 2026
A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform...
Low
Unreviewed
CVE-2026-12788
was published
Jun 21, 2026
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to...
Critical
Unreviewed
CVE-2026-47643
was published
Jun 9, 2026
Insufficient configuration management in the listed devices allows authenticated administrators...
Moderate
Unreviewed
CVE-2026-0418
was published
Jun 9, 2026
Apache Camel K: Kubernetes namespace authorized users can create a Build resource
High
CVE-2026-45760
was published
for
github.com/apache/camel-k/v2
(Go)
May 21, 2026
External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal...
High
Unreviewed
CVE-2026-30905
was published
May 13, 2026
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized...
High
Unreviewed
CVE-2026-41107
was published
May 12, 2026
External control of file name or path in SQL Server allows an authorized attacker to execute code...
High
Unreviewed
CVE-2026-40370
was published
May 12, 2026
External control of file name or path in Azure Monitor Agent allows an authorized attacker to...
High
Unreviewed
CVE-2026-32204
was published
May 12, 2026
Externally controlled reference to a resource in another sphere in Microsoft Partner Center...
High
Unreviewed
CVE-2026-34327
was published
May 8, 2026
OpenClaw: Workspace dotenv files cannot override connector endpoint hosts
Moderate
CVE-2026-45003
was published
for
openclaw
(npm)
May 4, 2026
An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0...
Moderate
Unreviewed
CVE-2026-30816
was published
Apr 8, 2026
An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows...
Moderate
Unreviewed
CVE-2026-30817
was published
Apr 8, 2026
A local file inclusion vulnerability in the upload/download flow of the VertiGIS FM application...
High
Unreviewed
CVE-2026-0522
was published
Apr 1, 2026
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6...
Critical
Unreviewed
CVE-2026-30903
was published
Mar 11, 2026
Local privilege escalation due to improper soft link handling. The following products are...
High
Unreviewed
CVE-2026-28721
was published
Mar 6, 2026
Local privilege escalation due to improper soft link handling. The following products are...
High
Unreviewed
CVE-2026-28722
was published
Mar 6, 2026
OpenClaw browser navigation guard allowed non-network URL schemes, enabling authenticated browser-tool users to access file:// local files
Moderate
CVE-2026-32008
was published
for
openclaw
(npm)
Mar 3, 2026
In onStart of CompanionDeviceManagerService.java, there is a possible confused deputy due to a...
High
Unreviewed
CVE-2025-48654
was published
Mar 2, 2026
A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the...
Low
Unreviewed
CVE-2026-3404
was published
Mar 2, 2026
ProTip!
Advisories are also available from the
GraphQL API