GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
30,740 advisories
Filter by severity
The Model Context Protocol has a security warning advising servers to validate the "Origin"...
Critical
Unreviewed
CVE-2026-11624
was published
Jun 13, 2026
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
Critical
CVE-2026-44990
was published
for
sanitize-html
(npm)
May 14, 2026
Naxclow devices use a server-side, per-device relay credential that never rotates and is re...
Critical
Unreviewed
CVE-2026-50101
was published
Jun 12, 2026
Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt...
Critical
Unreviewed
CVE-2026-28742
was published
Jun 12, 2026
QuTS hero is not affected.
We have already fixed the vulnerability in the following version:
QTS...
Critical
Unreviewed
CVE-2025-66276
was published
Jun 10, 2026
Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.
Critical
CVE-2026-47430
was published
for
cordova-plugin-inappbrowser
(npm)
Jun 8, 2026
NodeVM builtin denylist bypass via process and inspector/promises allows host code execution
Critical
CVE-2026-47140
was published
for
vm2
(npm)
May 29, 2026
vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
Critical
CVE-2026-47210
was published
for
vm2
(npm)
May 29, 2026
vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE
Critical
CVE-2026-47137
was published
for
vm2
(npm)
May 29, 2026
vm2 is Vulnerable to Sandbox Breakout Through Promise Species
Critical
CVE-2026-47208
was published
for
vm2
(npm)
May 29, 2026
BoxLite: Permission Bypass Allows Modification of Read-Only Files
Critical
CVE-2026-46695
was published
for
@boxlite-ai/boxlite
(Go)
May 21, 2026
Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
Critical
CVE-2026-46703
was published
for
@boxlite-ai/boxlite
(Go)
May 21, 2026
The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to...
Critical
Unreviewed
CVE-2026-50090
was published
Jun 12, 2026
Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same...
Critical
Unreviewed
CVE-2026-50091
was published
Jun 12, 2026
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication...
Critical
Unreviewed
CVE-2026-48558
was published
Jun 12, 2026
A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows...
Critical
Unreviewed
CVE-2026-45833
was published
Jun 12, 2026
The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid...
Critical
Unreviewed
CVE-2026-50084
was published
Jun 12, 2026
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which...
Critical
Unreviewed
CVE-2026-50083
was published
Jun 12, 2026
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against...
Critical
Unreviewed
CVE-2026-50086
was published
Jun 12, 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
Critical
Unreviewed
CVE-2026-35273
was published
Jun 11, 2026
Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
Critical
CVE-2026-48150
was published
for
@budibase/server
(npm)
Jun 12, 2026
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can...
Critical
Unreviewed
CVE-2026-50632
was published
Jun 12, 2026
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which...
Critical
Unreviewed
CVE-2026-50633
was published
Jun 12, 2026
Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a...
Critical
Unreviewed
CVE-2026-12027
was published
Jun 12, 2026
ProTip!
Advisories are also available from the
GraphQL API