GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,512
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,512
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
5,228 advisories
Filter by severity
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when...
High
Unreviewed
CVE-2026-73570
was published
Aug 13, 2026
GitPython versions before 3.1.54 contain a remote code execution vulnerability in the...
High
Unreviewed
CVE-2026-73625
was published
Aug 13, 2026
GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits -...
High
Unreviewed
CVE-2026-73623
was published
Aug 13, 2026
Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape...
Critical
Unreviewed
CVE-2026-73483
was published
Aug 13, 2026
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute...
High
Unreviewed
CVE-2026-16695
was published
Aug 12, 2026
IBM Informix Dynamic Server 14.10, 15.0, and 12.10 IBM Informix could allow an unauthenticated...
High
Unreviewed
CVE-2026-13476
was published
Aug 12, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
High
Unreviewed
CVE-2026-17417
was published
Aug 12, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
High
Unreviewed
CVE-2026-17642
was published
Aug 12, 2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0...
High
Unreviewed
CVE-2026-12005
was published
Aug 12, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
High
Unreviewed
CVE-2026-18235
was published
Aug 12, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security...
Moderate
Unreviewed
CVE-2026-17420
was published
Aug 12, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2026-16956
was published
Aug 12, 2026
IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with...
High
Unreviewed
CVE-2026-16906
was published
Aug 12, 2026
IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper...
High
Unreviewed
CVE-2026-16856
was published
Aug 12, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of...
High
Unreviewed
CVE-2026-17248
was published
Aug 12, 2026
Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote...
High
Unreviewed
CVE-2026-48553
was published
Aug 12, 2026
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote...
High
Unreviewed
CVE-2026-48554
was published
Aug 12, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An...
High
Unreviewed
CVE-2026-18683
was published
Aug 12, 2026
Description
Cloudflare was recently notified by external researchers of vulnerabilities in...
High
Unreviewed
CVE-2026-11325
was published
Aug 12, 2026
libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2)...
Critical
Unreviewed
CVE-2026-5917
was published
Aug 12, 2026
FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that...
High
Unreviewed
CVE-2026-14863
was published
Aug 11, 2026
Improper neutralization of special elements used in an os command ('os command injection') in...
High
Unreviewed
CVE-2026-70335
was published
Aug 11, 2026
Improper neutralization of special elements used in an os command ('os command injection') in...
High
Unreviewed
CVE-2026-69320
was published
Aug 11, 2026
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command (...
Critical
Unreviewed
CVE-2026-48362
was published
Aug 11, 2026
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command (...
High
Unreviewed
CVE-2026-48385
was published
Aug 11, 2026
ProTip!
Advisories are also available from the
GraphQL API