GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
388 advisories
Filter by severity
mathlive's Lack of Escaping of HTML allows for XSS
Moderate
CVE-2026-54705
was published
for
mathlive
(npm)
Jul 29, 2026
diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting...
Moderate
Unreviewed
CVE-2026-50642
was published
Jul 29, 2026
Shescape: Home-directory disclosure in assignment context on Unix with Dash
Moderate
GHSA-q53c-4prm-w95q
was published
for
shescape
(npm)
Jul 24, 2026
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
Moderate
GHSA-hc76-7mpc-qjqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
High
GHSA-pppj-hq3g-57pj
was published
for
jupyterlab
(pip)
Jul 22, 2026
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
Moderate
CVE-2026-64647
was published
for
next
(npm)
Jul 22, 2026
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
Moderate
CVE-2026-59895
was published
for
hono
(npm)
Jul 21, 2026
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
Low
CVE-2026-59727
was published
for
astro
(npm)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
Moderate
CVE-2026-50659
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and...
Critical
Unreviewed
CVE-2025-51677
was published
Jul 17, 2026
remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL...
High
Unreviewed
CVE-2026-63397
was published
Jul 16, 2026
A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect,...
High
Unreviewed
CVE-2026-15809
was published
Jul 15, 2026
Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could...
Critical
Unreviewed
CVE-2026-48358
was published
Jul 14, 2026
FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`
Low
CVE-2026-45710
was published
for
facturascripts/facturascripts
(Composer)
Jul 14, 2026
luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first...
High
Unreviewed
CVE-2026-62184
was published
Jul 14, 2026
Improper encoding of non-finite floating-point values during MapMessage JSON serialization in...
Moderate
Unreviewed
CVE-2026-49844
was published
Jul 11, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
CVE-2026-48598
was published
for
tesla
(Erlang)
Jul 10, 2026
YesWiki has stored XSS in Bazar form-field templates via unescaped field.label / field.hint (|raw('html'))
Moderate
CVE-2026-52772
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path
Low
GHSA-cwv4-h3j5-w3cf
was published
for
rama
(Rust)
Jul 7, 2026
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)
Moderate
CVE-2026-35366
was published
for
uu_printenv
(Rust)
Jul 6, 2026
comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output
Low
CVE-2026-35346
was published
for
uu_comm
(Rust)
Jul 6, 2026
Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log...
High
Unreviewed
CVE-2026-49091
was published
Jul 1, 2026
justhtml: to_markdown() code-span blank-line breakout enables XSS
Moderate
GHSA-jf6w-2mvx-633j
was published
for
justhtml
(pip)
Jun 25, 2026
An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic...
Low
Unreviewed
CVE-2026-40011
was published
Jun 25, 2026
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG...
Low
Unreviewed
CVE-2026-56379
was published
Jun 23, 2026
ProTip!
Advisories are also available from the
GraphQL API