GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
125 advisories
Filter by severity
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
High
GHSA-pppj-hq3g-57pj
was published
for
jupyterlab
(pip)
Jul 22, 2026
remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL...
High
Unreviewed
CVE-2026-63397
was published
Jul 16, 2026
A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect,...
High
Unreviewed
CVE-2026-15809
was published
Jul 15, 2026
luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first...
High
Unreviewed
CVE-2026-62184
was published
Jul 14, 2026
Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log...
High
Unreviewed
CVE-2026-49091
was published
Jul 1, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers
High
CVE-2026-57210
was published
for
https://github.com/dadrus/heimdall
(Go)
Jun 18, 2026
Open WebUI: Stored XSS to Account Takeover via Model Profile Images
High
CVE-2026-54013
was published
for
open-webui
(pip)
Jun 17, 2026
A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow...
High
Unreviewed
CVE-2026-20245
was published
Jun 5, 2026
Apostrophe has stored XSS via javascript: URL in Image Widget Link
High
CVE-2026-45011
was published
for
apostrophe
(npm)
May 14, 2026
phpMyFAQ has stored XSS via Utils::parseUrl() in comment rendering
High
CVE-2026-46367
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 6, 2026
YAFNET has Stored XSS in Forum Thread Posts/Replies that Allows Arbitrary JavaScript Execution for All Thread Viewers
High
CVE-2026-43939
was published
for
YAFNET.Core
(NuGet)
May 5, 2026
YAFNET has Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-Agent` Header
High
CVE-2026-43938
was published
for
YAFNET.Core
(NuGet)
May 5, 2026
Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS
High
CVE-2026-35569
was published
for
apostrophe
(npm)
Apr 16, 2026
Emissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in Executrix
High
CVE-2026-35582
was published
for
gov.nsa.emissary:emissary
(Maven)
Apr 13, 2026
Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
High
CVE-2026-34483
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 9, 2026
AWS SDK for .NET: Improper escaping of special characters in CloudFront policy document construction
High
GHSA-mvm6-f9r3-fgfx
was published
for
AWSSDK.CloudFront
(NuGet)
Mar 27, 2026
AWS SDK for Java 2.0: Improper Handling of Special Characters in CloudFront Signing Utilities
High
GHSA-443w-3rq3-5m5h
was published
for
software.amazon.awssdk:cloudfront
(Maven)
Mar 27, 2026
Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
High
CVE-2026-33941
was published
for
handlebars
(npm)
Mar 27, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string
High
CVE-2026-32811
was published
for
github.com/dadrus/heimdall
(Go)
Mar 18, 2026
jsPDF has a PDF Object Injection via FreeText color
High
CVE-2026-31898
was published
for
jspdf
(npm)
Mar 17, 2026
OpenClaw: fetch-guard forwards custom authorization headers across cross-origin redirects
High
CVE-2026-32913
was published
for
openclaw
(npm)
Mar 9, 2026
XWiki Blog Application home page vulnerable to Stored XSS via Post Title
High
CVE-2025-66024
was published
for
org.xwiki.contrib.blog:application-blog-ui
(Maven)
Mar 4, 2026
OpenClaw Windows Scheduled Task script generation allowed local command injection via unsafe cmd argument handling
High
CVE-2026-31994
was published
for
openclaw
(npm)
Mar 3, 2026
jsPDF has a PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property)
High
CVE-2026-25940
was published
for
jspdf
(npm)
Feb 19, 2026
jsPDF has a PDF Object Injection via Unsanitized Input in addJS Method
High
CVE-2026-25755
was published
for
jspdf
(npm)
Feb 19, 2026
ProTip!
Advisories are also available from the
GraphQL API