GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
117
GitHub Actions
55
Go
4,833
Maven
5,000+
npm
5,000+
NuGet
1,126
pip
5,000+
Pub
13
RubyGems
1,157
Rust
1,577
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
35,523 advisories
Filter by severity
OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm definitions, and script suites)
Critical
CVE-2026-77602
was published
for
openc3
(RubyGems)
Sep 23, 2026
orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator...
Critical
Unreviewed
CVE-2026-96754
was published
Sep 23, 2026
orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data...
Critical
Unreviewed
CVE-2026-96758
was published
Sep 23, 2026
orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted...
Critical
Unreviewed
CVE-2026-96757
was published
Sep 23, 2026
orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory...
Critical
Unreviewed
CVE-2026-96756
was published
Sep 23, 2026
orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated...
Critical
Unreviewed
CVE-2026-96759
was published
Sep 23, 2026
orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect...
Critical
Unreviewed
CVE-2026-96755
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site...
Critical
Unreviewed
CVE-2026-18872
was published
Sep 23, 2026
TarsWeb decides whether a request comes from a trusted local caller using a client-controlled...
Critical
Unreviewed
CVE-2026-80349
was published
Sep 23, 2026
Moquette: Pattern-ACL wildcard injection (cross-tenant authorization bypass) plus a remote-unauthenticated DoS cluster, a Will-message authorization bypass, and a cross-session durable-corruption bug
Critical
CVE-2026-85724
was published
for
io.moquette:moquette-broker
(Maven)
Sep 23, 2026
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure...
Critical
Unreviewed
CVE-2026-86708
was published
Sep 23, 2026
LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker...
Critical
Unreviewed
CVE-2026-96560
was published
Sep 23, 2026
ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code...
Critical
Unreviewed
CVE-2026-19599
was published
Sep 23, 2026
Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native...
Critical
Unreviewed
CVE-2026-86246
was published
Sep 23, 2026
plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection
Critical
CVE-2026-57149
was published
for
plone.app.portlets
(pip)
Sep 23, 2026
Improper link resolution before file access ('link following') vulnerability in the `tar` source...
Critical
Unreviewed
CVE-2026-82331
was published
Sep 23, 2026
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the...
Critical
Unreviewed
CVE-2026-82843
was published
Sep 23, 2026
The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files...
Critical
Unreviewed
CVE-2026-75799
was published
Sep 23, 2026
A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the...
Critical
Unreviewed
CVE-2026-96257
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to...
Critical
Unreviewed
CVE-2026-18162
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated...
Critical
Unreviewed
CVE-2026-18169
was published
Sep 23, 2026
A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same...
Critical
Unreviewed
CVE-2026-19202
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to...
Critical
Unreviewed
CVE-2026-18163
was published
Sep 23, 2026
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify...
Critical
Unreviewed
CVE-2026-17472
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to...
Critical
Unreviewed
CVE-2026-17635
was published
Sep 23, 2026
ProTip!
Advisories are also available from the
GraphQL API