GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
117
GitHub Actions
55
Go
4,836
Maven
5,000+
npm
5,000+
NuGet
1,126
pip
5,000+
Pub
13
RubyGems
1,157
Rust
1,577
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
3,066 advisories
Filter by severity
Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions.
High
Unreviewed
CVE-2026-95603
was published
Sep 23, 2026
MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the...
High
Unreviewed
CVE-2026-96804
was published
Sep 23, 2026
MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False...
High
Unreviewed
CVE-2026-96775
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated...
High
Unreviewed
CVE-2026-18490
was published
Sep 23, 2026
LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker...
Critical
Unreviewed
CVE-2026-96560
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to...
Critical
Unreviewed
CVE-2026-18163
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network...
High
Unreviewed
CVE-2026-17637
was published
Sep 23, 2026
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code...
High
Unreviewed
CVE-2026-28325
was published
Sep 22, 2026
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection...
Critical
Unreviewed
CVE-2026-43642
was published
Sep 22, 2026
SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution...
Critical
Unreviewed
CVE-2026-93088
was published
Sep 22, 2026
NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted...
High
Unreviewed
CVE-2026-65178
was published
Sep 22, 2026
NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an...
High
Unreviewed
CVE-2026-65179
was published
Sep 22, 2026
NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an...
High
Unreviewed
CVE-2026-24239
was published
Sep 22, 2026
NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer...
High
Unreviewed
CVE-2026-24267
was published
Sep 22, 2026
The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from...
High
Unreviewed
CVE-2026-91827
was published
Sep 22, 2026
The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up...
Critical
Unreviewed
CVE-2026-19658
was published
Sep 22, 2026
The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter...
Critical
Unreviewed
CVE-2026-94301
was published
Sep 21, 2026
The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability...
High
Unreviewed
CVE-2026-85017
was published
Sep 20, 2026
Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes...
High
Unreviewed
CVE-2026-93872
was published
Sep 18, 2026
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute...
Critical
Unreviewed
CVE-2026-81657
was published
Sep 18, 2026
IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in...
Moderate
Unreviewed
CVE-2026-11711
was published
Sep 18, 2026
IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary...
High
Unreviewed
CVE-2026-10751
was published
Sep 18, 2026
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
Critical
CVE-2025-66455
was published
for
lmdeploy
(pip)
Sep 18, 2026
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is...
High
Unreviewed
CVE-2026-17086
was published
Sep 18, 2026
The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated...
Critical
Unreviewed
CVE-2026-93467
was published
Sep 18, 2026
ProTip!
Advisories are also available from the
GraphQL API