GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,029
Maven
5,000+
npm
5,000+
NuGet
976
pip
5,000+
Pub
13
RubyGems
1,070
Rust
1,404
Swift
61
Unreviewed advisories
All unreviewed
5,000+
1,234 advisories
Filter by severity
VM2 Has Sandbox Breakout Through Promise Species
Critical
CVE-2026-24120
was published
for
vm2
(npm)
May 5, 2026
OpenMRS has Stored Velocity SSTI to RCE via ConceptReferenceRange
Critical
CVE-2026-41258
was published
for
org.openmrs.api:openmrs-api
(Maven)
May 4, 2026
VM2 Sandbox Breakout Through __lookupGetter__
Critical
CVE-2026-24118
was published
for
vm2
(npm)
May 4, 2026
Cockpit is vulnerable to arbitrary code execution
Critical
CVE-2026-38992
was published
for
cockpit-hq/cockpit
(Composer)
Apr 29, 2026
OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer...
Critical
Unreviewed
CVE-2026-27760
was published
Apr 28, 2026
ntfy.sh allows a remote attacker to execute arbitrary code via the parseActions function
Critical
CVE-2026-39087
was published
for
heckel.io/ntfy/v2
(Go)
Apr 23, 2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC...
Critical
Unreviewed
CVE-2026-39440
was published
Apr 23, 2026
Spinnaker: RCE via expression parsing due to unrestricted context handling
Critical
CVE-2026-32613
was published
for
io.spinnaker.echo:echo-pipelinetriggers
(Maven)
Apr 21, 2026
Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where...
Critical
Unreviewed
CVE-2026-39918
was published
Apr 20, 2026
SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file...
Critical
Unreviewed
CVE-2026-5760
was published
Apr 20, 2026
Remote Code Execution (RCE) via String Literal Injection into math-codegen
Critical
CVE-2026-41507
was published
for
math-codegen
(npm)
Apr 17, 2026
Arbitrary code execution in protobufjs
Critical
CVE-2026-41242
was published
for
protobufjs
(npm)
Apr 16, 2026
Flowise: Code Injection in CSVAgent leads to Authenticated RCE
Critical
CVE-2026-41137
was published
for
flowise
(npm)
Apr 16, 2026
Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)
Critical
CVE-2026-41229
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability...
Critical
Unreviewed
CVE-2026-30993
was published
Apr 15, 2026
WWBN AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaScript Execution via Client-Side eval() Sinks
Critical
CVE-2026-40911
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
Expression Injection in OpenRemote
Critical
CVE-2026-39842
was published
for
io.openremote:openremote-manager
(Maven)
Apr 14, 2026
OpenAI Codex CLI enables code execution through malicious MCP (Model Context Protocol) configuration files
Critical
CVE-2025-61260
was published
for
@openai/codex
(npm)
Apr 14, 2026
PraisonAI has critical RCE via `type: job` workflow YAML
Critical
CVE-2026-40288
was published
for
PraisonAI
(pip)
Apr 10, 2026
A Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows...
Critical
Unreviewed
CVE-2026-30479
was published
Apr 9, 2026
SiYuan: Remote Code Execution in the Electron desktop client via stored XSS in synced table captions
Critical
CVE-2026-39846
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Apr 8, 2026
Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow...
Critical
Unreviewed
CVE-2026-25776
was published
Apr 8, 2026
Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that...
Critical
Unreviewed
CVE-2025-71058
was published
Apr 7, 2026
Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping,...
Critical
Unreviewed
CVE-2024-36057
was published
Apr 7, 2026
Kedro has Arbitrary Code Execution via Malicious Logging Configuration
Critical
CVE-2026-35171
was published
for
kedro
(pip)
Apr 3, 2026
ProTip!
Advisories are also available from the
GraphQL API