GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,722
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,568
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
369,656 advisories
Filter by severity
Velociraptor allows for the creation of notebook backups in its default enabled daily backup...
High
Unreviewed
CVE-2026-19584
was published
Sep 10, 2026
BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user...
Moderate
Unreviewed
CVE-2026-84062
was published
Sep 10, 2026
The Ninja Forms - Scheduled Exports plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2026-87870
was published
Sep 10, 2026
BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with...
High
Unreviewed
CVE-2026-84063
was published
Sep 10, 2026
A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function...
Moderate
Unreviewed
CVE-2026-87933
was published
Sep 10, 2026
Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example,...
Critical
Unreviewed
CVE-2026-19583
was published
Sep 10, 2026
The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary...
Critical
Unreviewed
CVE-2026-18351
was published
Sep 10, 2026
Pandora contains a path traversal vulnerability in its archive extraction worker. When processing...
Critical
Unreviewed
CVE-2026-88069
was published
Sep 10, 2026
Authentication Bypass via Hardcoded Master Verification Code vulnerability in Siam Ordering (siam...
Unknown
Unreviewed
CVE-2026-71809
was published
Sep 10, 2026
A security vulnerability has been detected in Rizwan17 inventory-management-system up to...
Moderate
Unreviewed
CVE-2026-87924
was published
Sep 10, 2026
A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning...
High
Unreviewed
CVE-2026-87931
was published
Sep 10, 2026
A vulnerability was detected in Rizwan17 inventory-management-system up to...
Moderate
Unreviewed
CVE-2026-87925
was published
Sep 10, 2026
A flaw has been found in Rizwan17 inventory-management-system up to...
Low
Unreviewed
CVE-2026-87926
was published
Sep 10, 2026
A weakness has been identified in Rizwan17 inventory-management-system up to...
Low
Unreviewed
CVE-2026-87923
was published
Sep 10, 2026
A security flaw has been discovered in Rizwan17 inventory-management-system up to...
Moderate
Unreviewed
CVE-2026-87922
was published
Sep 10, 2026
In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of...
High
Unreviewed
CVE-2026-15913
was published
Sep 10, 2026
An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0....
Unknown
Unreviewed
CVE-2026-71805
was published
Sep 10, 2026
In RuoYi-Cloud-Plus <= 2.6.2 in the ruoyi-workflow module, multiple core task APIs in...
Unknown
Unreviewed
CVE-2026-71807
was published
Sep 10, 2026
zhitan-ems 1.0.0 is vulnerable to Cross Site Scripting (XSS) via SVG file upload through the ...
Unknown
Unreviewed
CVE-2026-75307
was published
Sep 10, 2026
A vulnerability was identified in Rizwan17 inventory-management-system up to...
Moderate
Unreviewed
CVE-2026-87921
was published
Sep 10, 2026
yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload...
Unknown
Unreviewed
CVE-2026-75308
was published
Sep 10, 2026
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
Moderate
CVE-2026-88000
was published
for
open-webui
(pip)
Sep 9, 2026
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
Moderate
CVE-2026-88001
was published
for
open-webui
(pip)
Sep 9, 2026
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
Moderate
CVE-2026-88002
was published
for
open-webui
(pip)
Sep 9, 2026
Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
High
CVE-2026-59185
was published
for
github.com/identrail/identrail
(Go)
Sep 9, 2026
ProTip!
Advisories are also available from the
GraphQL API