GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
1,219 advisories
Filter by severity
A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows...
Critical
Unreviewed
CVE-2026-45833
was published
Jun 12, 2026
PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground
Critical
CVE-2026-8467
was published
for
phoenix_storybook
(Erlang)
Jun 9, 2026
WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that...
Critical
Unreviewed
CVE-2017-20251
was published
Jun 9, 2026
Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS Chrome Plugin
Critical
CVE-2026-47252
was published
for
github.com/julien040/anyquery/plugins/brave
(Go)
Jun 8, 2026
DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
Critical
CVE-2026-47668
was published
for
dbgate-serve
(npm)
Jun 5, 2026
OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter...
Critical
Unreviewed
CVE-2026-47117
was published
Jun 2, 2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by...
Critical
Unreviewed
CVE-2026-9311
was published
Jun 1, 2026
A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3...
Critical
Unreviewed
CVE-2026-8931
was published
Jun 1, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
CVE-2026-8838
was published
for
redshift-connector
(pip)
May 29, 2026
Insufficient character filtering in backup agent signing module on Comet Backup server allows...
Critical
Unreviewed
CVE-2026-32999
was published
May 28, 2026
Yamcs Vulnerable to Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection
Critical
CVE-2026-46621
was published
for
org.yamcs:yamcs-core
(Maven)
May 27, 2026
Yamcs Vulnerable to Remote Code Execution via Mission Database algorithm override
Critical
CVE-2026-46562
was published
for
org.yamcs:yamcs-core
(Maven)
May 27, 2026
Langroid has Prompt to SQL Injection, Leading to RCE
Critical
CVE-2026-25879
was published
for
langroid
(pip)
May 27, 2026
LiquidJS is Vulnerable to Remote Code Execution
Critical
CVE-2026-45618
was published
for
liquidjs
(npm)
May 27, 2026
Yamcs Vulnerable to Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`
Critical
CVE-2026-44632
was published
for
org.yamcs:yamcs-core
(Maven)
May 27, 2026
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM...
Critical
Unreviewed
CVE-2026-8633
was published
May 26, 2026
Dolibarr ERP CRM 7.0.3 contains a remote code evaluation vulnerability that allows...
Critical
Unreviewed
CVE-2018-25357
was published
May 26, 2026
Twig: PHP code injection via `{% use %}` template name
Critical
CVE-2026-46633
was published
for
twig/twig
(Composer)
May 21, 2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client...
Critical
Unreviewed
CVE-2026-22314
was published
May 20, 2026
scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the...
Critical
Unreviewed
CVE-2026-30117
was published
May 19, 2026
GlassFish's Administration Console is Vulnerable to RCE
Critical
CVE-2026-2586
was published
for
org.glassfish.jsftemplating:jsftemplating
(Maven)
May 19, 2026
ChromaDB Python project has a pre-authentication code injection vulnerability
Critical
CVE-2026-45829
was published
for
chromadb
(pip)
May 18, 2026
Formie: Pre-authenticated server-side template injection in Hidden fields
Critical
CVE-2026-45697
was published
for
verbb/formie
(Composer)
May 18, 2026
ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability...
Critical
Unreviewed
CVE-2018-25320
was published
May 17, 2026
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to...
Critical
Unreviewed
CVE-2021-47952
was published
May 16, 2026
ProTip!
Advisories are also available from the
GraphQL API