GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
5,498 advisories
Filter by severity
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java...
Critical
Unreviewed
CVE-2026-67340
was published
Aug 1, 2026
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2026-16144
was published
Aug 1, 2026
sentence-transformers contains a security control bypass vulnerability that allows attackers to...
Critical
Unreviewed
CVE-2026-68770
was published
Jul 31, 2026
Savon::Model evaluates WSDL operation names as Ruby source
High
CVE-2026-53510
was published
for
savon
(RubyGems)
Jul 31, 2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software,...
Critical
Unreviewed
CVE-2026-17561
was published
Jul 31, 2026
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom...
High
Unreviewed
CVE-2026-13392
was published
Jul 31, 2026
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on...
Critical
Unreviewed
CVE-2026-12946
was published
Jul 30, 2026
IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the...
Critical
Unreviewed
CVE-2026-13435
was published
Jul 30, 2026
The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing...
Critical
Unreviewed
CVE-2026-14602
was published
Jul 30, 2026
Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a...
High
Unreviewed
CVE-2026-17922
was published
Jul 30, 2026
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
High
CVE-2026-11393
was published
for
@aws/agentcore
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
High
CVE-2026-54666
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped enum string values
High
CVE-2026-54664
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
High
CVE-2026-54661
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
High
CVE-2026-54662
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in...
Critical
Unreviewed
CVE-2026-14900
was published
Jul 29, 2026
The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce...
Critical
Unreviewed
CVE-2026-13423
was published
Jul 29, 2026
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
High
CVE-2026-54654
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
High
CVE-2026-54653
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data
High
CVE-2026-54656
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
High
CVE-2026-55415
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
High
CVE-2026-54621
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
High
CVE-2026-54655
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session...
High
Unreviewed
CVE-2026-66745
was published
Jul 28, 2026
Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution...
High
Unreviewed
CVE-2026-66748
was published
Jul 28, 2026
ProTip!
Advisories are also available from the
GraphQL API