GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
5,140 advisories
Filter by severity
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account...
High
Unreviewed
CVE-2026-67325
was published
Aug 1, 2026
GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form...
Critical
Unreviewed
CVE-2026-67324
was published
Aug 1, 2026
Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that...
Moderate
Unreviewed
CVE-2026-67308
was published
Aug 1, 2026
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This...
High
Unreviewed
CVE-2026-9044
was published
Aug 1, 2026
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an...
High
Unreviewed
CVE-2026-17347
was published
Jul 31, 2026
pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a...
Critical
Unreviewed
CVE-2026-17566
was published
Jul 31, 2026
Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to...
High
Unreviewed
CVE-2026-16843
was published
Jul 31, 2026
IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management...
Critical
Unreviewed
CVE-2026-12943
was published
Jul 30, 2026
IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution...
Critical
Unreviewed
CVE-2026-12940
was published
Jul 30, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow...
High
Unreviewed
CVE-2026-14522
was published
Jul 30, 2026
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
Moderate
CVE-2026-67438
was published
for
github.com/OliveTin/OliveTin
(Go)
Jul 30, 2026
Improper input validation in one of the session management interface of Eaton's Tripp Lite Series...
High
Unreviewed
CVE-2026-22621
was published
Jul 30, 2026
Improper input validation in one of the session management interface of Eaton's Tripp Lite series...
High
Unreviewed
CVE-2026-22622
was published
Jul 30, 2026
A privilege escalation vulnerability in the init-script for user-applications allows a low...
High
Unreviewed
CVE-2026-44106
was published
Jul 30, 2026
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute...
High
Unreviewed
CVE-2026-44096
was published
Jul 30, 2026
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend...
High
Unreviewed
CVE-2026-44098
was published
Jul 30, 2026
A local privilege escalation vulnerability in the init-script for user-applications allows a low...
High
Unreviewed
CVE-2026-44093
was published
Jul 30, 2026
A privilege escalation vulnerability in a script used for network configuration allows a low...
High
Unreviewed
CVE-2026-44095
was published
Jul 30, 2026
A privilege escalation vulnerability in the system configuration allows a low-privileged local...
High
Unreviewed
CVE-2026-44099
was published
Jul 30, 2026
A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via...
High
Unreviewed
CVE-2026-16524
was published
Jul 30, 2026
GNU Bison allows for an execution of an arbitrary program during HTML report generation due to...
Moderate
Unreviewed
CVE-2026-56389
was published
Jul 29, 2026
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute...
Critical
Unreviewed
CVE-2026-14958
was published
Jul 28, 2026
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute...
Critical
Unreviewed
CVE-2026-14959
was published
Jul 28, 2026
ELECOM wireless LAN routers and access points devices contain an OS Command Injection...
High
Unreviewed
CVE-2026-59764
was published
Jul 28, 2026
ELECOM wireless LAN routers and access points devices contain an OS Command Injection...
High
Unreviewed
CVE-2026-61376
was published
Jul 28, 2026
ProTip!
Advisories are also available from the
GraphQL API