GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,347 advisories
Filter by severity
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
Critical
CVE-2026-71851
was published
for
crypto-js
(npm)
Aug 7, 2026
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
Critical
CVE-2026-71319
was published
for
@nuxt/devtools
(npm)
Aug 5, 2026
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
Critical
CVE-2026-70478
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Critical
CVE-2026-70477
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
Critical
CVE-2026-69264
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
Critical
CVE-2026-70470
was published
for
flowise
(npm)
Aug 4, 2026
Flowise RCE via SQLite Record Manager Node
Critical
CVE-2026-69259
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Remote Code Execution Vulnerability in CSVAgent
Critical
CVE-2026-69256
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
Critical
CVE-2026-69255
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
Critical
CVE-2026-69254
was published
for
flowise
(npm)
Aug 4, 2026
Flowise RCE via TypeORM DataSource
Critical
CVE-2026-69251
was published
for
flowise
(npm)
Aug 4, 2026
Sequelize: SQL Injection (Oracle DB)
Critical
CVE-2026-69240
was published
for
sequelize
(npm)
Aug 3, 2026
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
Critical
CVE-2026-53609
was published
for
apostrophe
(npm)
Jul 31, 2026
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
Critical
CVE-2026-52887
was published
for
@nocobase/plugin-notification-in-app-message
(npm)
Jul 31, 2026
AWS Amplify Studio UI Component Properties Has an Input Validation Issue
Critical
CVE-2025-4318
was published
for
@aws-amplify/codegen-ui-react
(npm)
Jul 30, 2026
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
Critical
CVE-2026-54658
was published
for
@hypequery/clickhouse
(npm)
Jul 28, 2026
Shescape: Shell injection via unescaped parentheses on Windows with CMD
Critical
GHSA-w4hw-qcx7-56pr
was published
for
shescape
(npm)
Jul 24, 2026
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
Critical
GHSA-vh45-f885-3848
was published
for
sm-crypto
(npm)
Jul 24, 2026
Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
Critical
GHSA-mqhr-6j6h-74p5
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
Critical
GHSA-hp6v-6jw7-gv2f
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: SQL Injection via `multipleStatements: true`
Critical
GHSA-q6x4-v3qx-85qw
was published
for
@budibase/server
(npm)
Jul 24, 2026
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
Critical
GHSA-w28w-gp39-m4p6
was published
for
@prompty/core
(npm)
Jul 24, 2026
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
Critical
GHSA-7gfh-x38p-prh3
was published
for
velocityjs
(npm)
Jul 24, 2026
seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
Critical
CVE-2026-59940
was published
for
seroval
(npm)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API