GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,029
Maven
5,000+
npm
5,000+
NuGet
976
pip
5,000+
Pub
13
RubyGems
1,070
Rust
1,404
Swift
61
Unreviewed advisories
All unreviewed
5,000+
964 advisories
Filter by severity
Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
High
CVE-2026-46640
was published
for
twig/twig
(Composer)
May 21, 2026
Twig: PHP code injection via `{% use %}` template name
Critical
CVE-2026-46633
was published
for
twig/twig
(Composer)
May 21, 2026
lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
High
CVE-2026-46517
was published
for
lmdeploy
(pip)
May 21, 2026
LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
High
CVE-2026-46432
was published
for
lmdeploy
(pip)
May 21, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
High
CVE-2025-51427
was published
for
modelscope
(pip)
May 19, 2026
GlassFish's Administration Console is Vulnerable to RCE
Critical
CVE-2026-2586
was published
for
org.glassfish.jsftemplating:jsftemplating
(Maven)
May 19, 2026
ChromaDB Python project has a pre-authentication code injection vulnerability
Critical
CVE-2026-45829
was published
for
chromadb
(pip)
May 18, 2026
Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API
Moderate
CVE-2026-45719
was published
for
@budibase/server
(npm)
May 18, 2026
Formie: Pre-authenticated server-side template injection in Hidden fields
Critical
CVE-2026-45697
was published
for
verbb/formie
(Composer)
May 18, 2026
Apache Flink: Remote code execution via SQL injection in code generation
High
CVE-2026-35194
was published
for
org.apache.flink:flink-table-api-java
(Maven)
May 15, 2026
Crabbox: environment variable exposure vulnerability
Critical
CVE-2026-8634
was published
for
github.com/openclaw/crabbox
(Go)
May 14, 2026
Electerm Local code through electerm's single-instance socket
Critical
CVE-2026-45353
was published
for
electerm
(npm)
May 14, 2026
DeepSeek TUI: task_create Insecure Defaults Enable RCE via Prompt Injection in Project Files
Critical
CVE-2026-45374
was published
for
deepseek-tui
(Rust)
May 14, 2026
DeepSeek TUI: run_tests Tool Enables RCE via Malicious Repository Without Approval
Critical
CVE-2026-45311
was published
for
deepseek-tui
(npm)
May 14, 2026
Electerm: Importing unsafe bookmark data could lead to unsafe operation when clicking local type bookmark
Critical
CVE-2026-45058
was published
for
electerm
(npm)
May 14, 2026
FlowiseAI: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
Critical
CVE-2026-46442
was published
for
flowise
(npm)
May 14, 2026
CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request_target` Configuration
High
CVE-2026-41249
was published
for
coreshop/core-shop
(Composer)
May 14, 2026
claude-code-cache-fix vulnerable to local code execution via Python triple-quote injection in tools/quota-statusline.sh
High
CVE-2026-45136
was published
for
claude-code-cache-fix
(npm)
May 13, 2026
Mapfish Print: Remote Code Injection (RCE) in Dynamic table
Critical
CVE-2026-44672
was published
for
org.mapfish.print:print-lib
(Maven)
May 13, 2026
llm CLI tool contains a code injection vulnerability via `--functions` command-line argument
Critical
CVE-2026-31236
was published
for
llm
(pip)
May 12, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
Critical
CVE-2026-31233
was published
for
guardrails-ai
(pip)
May 12, 2026
Superduper: Remote code execution via unsafe eval in superduper query parsing
High
CVE-2026-31225
was published
for
superduper-framework
(pip)
May 12, 2026
PySyft server-side arbitrary Python execution after code approval
Critical
CVE-2026-31220
was published
for
syft
(pip)
May 12, 2026
protobuf.js: Code injection in pbjs static output from crafted schema names
High
CVE-2026-44295
was published
for
protobufjs-cli
(npm)
May 12, 2026
protobuf.js: Code injection through bytes field defaults in generated toObject code
High
CVE-2026-44293
was published
for
protobufjs
(npm)
May 12, 2026
ProTip!
Advisories are also available from the
GraphQL API