GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
4,270 advisories
Filter by severity
Formie: Pre-authenticated server-side template injection in Hidden fields
Critical
CVE-2026-45697
was published
for
verbb/formie
(Composer)
May 18, 2026
Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs
Critical
CVE-2026-45625
was published
for
github.com/getarcaneapp/arcane/backend
(Go)
May 18, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
Critical
CVE-2026-7302
was published
for
sglang
(pip)
May 18, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
Critical
CVE-2026-7301
was published
for
sglang
(pip)
May 18, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
Critical
CVE-2026-7304
was published
for
sglang
(pip)
May 18, 2026
Duplicate Advisory: phpMyFAQ has unauthenticated SQL injection via User-Agent header in BuiltinCaptcha
Critical
GHSA-ch9q-c9mp-j5gq
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 15, 2026
•
withdrawn
Duplicate Advisory: phpMyFAQ enables unauthenticated 2FA brute-force attack via /admin/check acceptance of arbitrary user-id
Critical
GHSA-6626-79jh-5ccr
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 15, 2026
•
withdrawn
Crabbox: environment variable exposure vulnerability
Critical
CVE-2026-8634
was published
for
github.com/openclaw/crabbox
(Go)
May 14, 2026
vm2 Has a Sandbox Breakout Using Async Generator
Critical
CVE-2026-45411
was published
for
vm2
(npm)
May 14, 2026
utcp-cli Vulnerable to Command Injection via Unsanitized Argument Substitution in CLI Communication Protocol
Critical
CVE-2026-45369
was published
for
utcp-cli
(pip)
May 14, 2026
Marten has an injection vulnerability in its full-text search regConfig parameter
Critical
CVE-2026-45288
was published
for
Marten
(NuGet)
May 14, 2026
@samanhappy/mcphub: SSE Endpoint Accepts Arbitrary Username from URL Path Without Authentication, Enabling User Impersonation
Critical
GHSA-wf8q-wvv8-p8jf
was published
for
@samanhappy/mcphub
(npm)
May 14, 2026
Electerm Local code through electerm's single-instance socket
Critical
CVE-2026-45353
was published
for
electerm
(npm)
May 14, 2026
DeepSeek TUI: task_create Insecure Defaults Enable RCE via Prompt Injection in Project Files
Critical
CVE-2026-45374
was published
for
deepseek-tui
(Rust)
May 14, 2026
DeepSeek TUI: run_tests Tool Enables RCE via Malicious Repository Without Approval
Critical
CVE-2026-45311
was published
for
deepseek-tui
(npm)
May 14, 2026
Electerm: Importing unsafe bookmark data could lead to unsafe operation when clicking local type bookmark
Critical
CVE-2026-45058
was published
for
electerm
(npm)
May 14, 2026
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
Critical
CVE-2026-44990
was published
for
sanitize-html
(npm)
May 14, 2026
Portainer has an endpoint security bypass via Swarm service create/update
Critical
CVE-2026-44849
was published
for
github.com/portainer/portainer
(Go)
May 14, 2026
Portainer missing authorization on Docker plugin endpoints, which allows host RCE
Critical
CVE-2026-44848
was published
for
github.com/portainer/portainer
(Go)
May 14, 2026
n8n Has an XML Node Prototype Pollution Patch Bypass
Critical
CVE-2026-44791
was published
for
n8n
(npm)
May 14, 2026
n8n Has an Arbitrary File Read via Git Node
Critical
CVE-2026-44790
was published
for
n8n
(npm)
May 14, 2026
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
Critical
CVE-2026-44789
was published
for
n8n
(npm)
May 14, 2026
FlowiseAI: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
Critical
CVE-2026-46442
was published
for
flowise
(npm)
May 14, 2026
Strapi may leak sensitive data via relational filtering due to lack of query sanitization
Critical
CVE-2026-27886
was published
for
@strapi/strapi
(npm)
May 14, 2026
Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading
Critical
CVE-2026-8178
was published
for
com.amazon.redshift:redshift-jdbc42
(Maven)
May 14, 2026
ProTip!
Advisories are also available from the
GraphQL API