GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,569
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,522
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
149 advisories
Filter by severity
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in...
High
Unreviewed
CVE-2026-78136
was published
Aug 23, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
Critical
CVE-2026-61539
was published
for
xinference
(pip)
Aug 21, 2026
@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers...
High
Unreviewed
CVE-2026-76833
was published
Aug 20, 2026
Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to...
Moderate
Unreviewed
CVE-2026-74234
was published
Aug 17, 2026
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in...
Critical
Unreviewed
CVE-2026-74899
was published
Aug 17, 2026
A remote code execution vulnerability exists in Tenable Security Center's report generation...
Critical
Unreviewed
CVE-2026-19626
was published
Aug 14, 2026
Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP...
Critical
Unreviewed
CVE-2026-73601
was published
Aug 13, 2026
Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that...
Critical
Unreviewed
CVE-2026-73602
was published
Aug 13, 2026
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
Critical
CVE-2026-69264
was published
for
flowise
(npm)
Aug 4, 2026
Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated...
High
Unreviewed
CVE-2026-67195
was published
Aug 4, 2026
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in...
Critical
Unreviewed
CVE-2026-48317
was published
Aug 4, 2026
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category...
Critical
Unreviewed
CVE-2026-39932
was published
Aug 3, 2026
SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for...
Critical
Unreviewed
CVE-2026-15971
was published
Jul 30, 2026
AWS Amplify Studio UI Component Properties Has an Input Validation Issue
Critical
CVE-2025-4318
was published
for
@aws-amplify/codegen-ui-react
(npm)
Jul 30, 2026
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
High
CVE-2026-55415
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
High
CVE-2026-45293
was published
for
wp-coding-standards/wpcs
(Composer)
Jul 28, 2026
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the...
Critical
Unreviewed
CVE-2026-61511
was published
Jul 27, 2026
NLTK vulnerable to Eval Injection via collocations CLI arguments
High
CVE-2025-71408
was published
for
nltk
(pip)
Jul 25, 2026
Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR....
Critical
Unreviewed
CVE-2026-64193
was published
Jul 20, 2026
django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization
High
GHSA-r3hx-x5rh-p9vv
was published
for
django-haystack
(pip)
Jul 15, 2026
MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php
High
CVE-2026-49273
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
Critical
CVE-2026-61667
was published
for
DIRAC
(pip)
Jul 13, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
Critical
CVE-2026-45579
was published
for
DIRAC
(pip)
Jul 13, 2026
EGroupware has Authenticated RCE via Malicious eTemplate Upload
High
CVE-2026-40187
was published
for
egroupware/egroupware
(Composer)
Jul 7, 2026
ProTip!
Advisories are also available from the
GraphQL API