GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
392 advisories
Filter by severity
SiYuan: Electron Renderer RCE via decodeURIComponent-driven tooltip XSS in aria-label sink (incomplete fix for CVE-2026-34585)
Critical
CVE-2026-44588
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
May 8, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`
Moderate
CVE-2026-44429
was published
for
github.com/modelcontextprotocol/registry
(Go)
May 8, 2026
If a trusted template author were to write a <script> tag containing an empty 'type' attribute or...
Moderate
Unreviewed
CVE-2026-39826
was published
May 7, 2026
Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers
Moderate
GHSA-3v85-fqvh-7rxf
was published
for
github.com/lin-snow/Ech0
(Go)
May 7, 2026
phpMyFAQ has stored XSS via Utils::parseUrl() in comment rendering
High
CVE-2026-46367
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 6, 2026
YAFNET has Stored XSS in Forum Thread Posts/Replies that Allows Arbitrary JavaScript Execution for All Thread Viewers
High
CVE-2026-43939
was published
for
YAFNET.Core
(NuGet)
May 5, 2026
YAFNET has Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-Agent` Header
High
CVE-2026-43938
was published
for
YAFNET.Core
(NuGet)
May 5, 2026
Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
Low
CVE-2026-42040
was published
for
axios
(npm)
May 5, 2026
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for...
Low
Unreviewed
CVE-2026-6019
was published
Apr 22, 2026
** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program...
Moderate
Unreviewed
CVE-2026-6058
was published
Apr 21, 2026
pretalx mail templates vulnerable to email injection via unescaped user-controlled placeholders
Moderate
CVE-2026-41426
was published
for
pretalx
(pip)
Apr 18, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering
Moderate
CVE-2026-40302
was published
for
github.com/openziti/zrok
(Go)
Apr 16, 2026
Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS
High
CVE-2026-35569
was published
for
apostrophe
(npm)
Apr 16, 2026
A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive...
Moderate
Unreviewed
CVE-2026-20136
was published
Apr 15, 2026
CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log...
Moderate
Unreviewed
CVE-2026-2404
was published
Apr 14, 2026
Emissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in Executrix
High
CVE-2026-35582
was published
for
gov.nsa.emissary:emissary
(Maven)
Apr 13, 2026
Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
Moderate
CVE-2026-34479
was published
for
org.apache.logging.log4j:log4j-1.2-api
(Maven)
Apr 10, 2026
Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
Moderate
CVE-2026-34481
was published
for
org.apache.logging.log4j:log4j-layout-template-json
(Maven)
Apr 10, 2026
Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0...
Moderate
Unreviewed
CVE-2026-40023
was published
Apr 10, 2026
Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters
Moderate
CVE-2026-40021
was published
for
log4net
(NuGet)
Apr 10, 2026
Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
Moderate
CVE-2026-34480
was published
for
org.apache.logging.log4j:log4j-core
(Maven)
Apr 10, 2026
Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
High
CVE-2026-34483
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 9, 2026
OpenClaw has ACP CLI approval prompt ANSI escape sequence injection
Moderate
CVE-2026-35651
was published
for
openclaw
(npm)
Mar 29, 2026
AWS SDK for .NET: Improper escaping of special characters in CloudFront policy document construction
High
GHSA-mvm6-f9r3-fgfx
was published
for
AWSSDK.CloudFront
(NuGet)
Mar 27, 2026
ProTip!
Advisories are also available from the
GraphQL API