GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,093
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
133 advisories
Filter by severity
An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type...
Critical
Unreviewed
CVE-2026-52439
was published
Jul 23, 2026
n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
High
CVE-2026-65591
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
High
GHSA-m7jc-p4hf-xhwq
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST...
High
Unreviewed
CVE-2026-57281
was published
Jun 24, 2026
Improper neutralization of special elements used in an expression language statement ('expression...
Moderate
Unreviewed
CVE-2026-11561
was published
Jun 11, 2026
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious...
Moderate
Unreviewed
CVE-2026-40985
was published
Jun 11, 2026
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when...
High
Unreviewed
CVE-2026-41729
was published
Jun 10, 2026
A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is...
Moderate
Unreviewed
CVE-2026-41719
was published
Jun 10, 2026
Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection...
High
Unreviewed
CVE-2026-41717
was published
Jun 10, 2026
Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server...
High
Unreviewed
CVE-2026-8888
was published
Jun 3, 2026
Caddy CVE-2026-30852 Fix Bypass
Moderate
GHSA-wwhq-w58m-w29c
was published
for
github.com/caddyserver/caddy/v2
(Go)
May 19, 2026
GlassFish's gadget handler is vulnerable to RCE
Critical
CVE-2026-2587
was published
for
org.glassfish.jsftemplating:jsftemplating
(Maven)
May 19, 2026
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression...
Moderate
Unreviewed
CVE-2026-31380
was published
May 19, 2026
Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron...
High
Unreviewed
CVE-2026-26462
was published
May 18, 2026
Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs
High
CVE-2026-41705
was published
for
org.springframework.ai:spring-ai-milvus-store
(Maven)
May 9, 2026
Sandboxed Thymeleaf expressions vulnerable to improper recognition of unauthorized syntax patterns
Critical
CVE-2026-41901
was published
for
org.thymeleaf:thymeleaf
(Maven)
May 4, 2026
OmniFaces: EL injection via crafted resource name in wildcard CDN mapping
High
CVE-2026-41883
was published
for
org.omnifaces:omnifaces
(Maven)
Apr 16, 2026
Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
Critical
CVE-2026-40478
was published
for
org.thymeleaf:thymeleaf
(Maven)
Apr 15, 2026
Improper restriction of the scope of accessible objects in Thymeleaf expressions
Critical
CVE-2026-40477
was published
for
org.thymeleaf:thymeleaf
(Maven)
Apr 15, 2026
Expression Injection in OpenRemote
Critical
CVE-2026-39842
was published
for
io.openremote:openremote-manager
(Maven)
Apr 14, 2026
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in...
Critical
Unreviewed
CVE-2026-34714
was published
Mar 30, 2026
Spring AI: SpEL injection is triggered when a user-supplied value is used as a filter expression key
Critical
CVE-2026-22738
was published
for
org.springframework.ai:spring-ai-vector-store
(Maven)
Mar 27, 2026
JSONPath Injection in Spring AI Vector Stores FilterExpressionConverter
High
CVE-2026-22729
was published
for
org.springframework.ai:spring-ai-vector-store
(Maven)
Mar 18, 2026
Apache IoTDB has an Improper Input Validation vulnerability
Critical
CVE-2026-24713
was published
for
org.apache.iotdb:iotdb-core
(Maven)
Mar 9, 2026
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression...
High
Unreviewed
CVE-2025-11175
was published
Jan 30, 2026
ProTip!
Advisories are also available from the
GraphQL API