GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
44,695 advisories
Filter by severity
A security vulnerability has been detected in yaojingang GEOFlow up to 2.1.0. This affects an...
Low
Unreviewed
CVE-2026-82664
was published
Aug 31, 2026
A vulnerability has been found in code-projects Simple Inventory System 1.0. This affects an...
Low
Unreviewed
CVE-2026-82625
was published
Aug 31, 2026
A security vulnerability has been detected in code-projects Employee Leave Managing System 1.0....
Low
Unreviewed
CVE-2026-82622
was published
Aug 31, 2026
NSP is vulnerable to a stored XSS due to insufficient validation or encoding of user-controlled...
Moderate
Unreviewed
CVE-2026-40464
was published
Aug 31, 2026
A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file ...
Low
Unreviewed
CVE-2026-82601
was published
Aug 31, 2026
A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part...
Low
Unreviewed
CVE-2026-82554
was published
Aug 30, 2026
WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the...
Moderate
Unreviewed
CVE-2026-82646
was published
Aug 30, 2026
SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog()...
Critical
Unreviewed
CVE-2026-82653
was published
Aug 30, 2026
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint,...
Critical
Unreviewed
CVE-2026-82654
was published
Aug 30, 2026
Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB...
High
Unreviewed
CVE-2026-82642
was published
Aug 30, 2026
A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown...
Low
Unreviewed
CVE-2026-82488
was published
Aug 30, 2026
A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1...
Low
Unreviewed
CVE-2026-82482
was published
Aug 30, 2026
A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This...
Low
Unreviewed
CVE-2026-82483
was published
Aug 30, 2026
The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does...
High
Unreviewed
CVE-2026-81660
was published
Aug 30, 2026
The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not...
Moderate
Unreviewed
CVE-2026-14835
was published
Aug 30, 2026
The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters...
High
Unreviewed
CVE-2026-14307
was published
Aug 30, 2026
The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form...
Low
Unreviewed
CVE-2026-78364
was published
Aug 30, 2026
The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape...
High
Unreviewed
CVE-2026-76585
was published
Aug 30, 2026
Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking...
Moderate
Unreviewed
CVE-2026-82451
was published
Aug 29, 2026
The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its...
Moderate
Unreviewed
CVE-2026-76546
was published
Aug 29, 2026
silverstripe/versioned has XSS in archive admin restore
Moderate
CVE-2026-55779
was published
for
silverstripe/versioned
(Composer)
Aug 28, 2026
MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before...
Moderate
Unreviewed
CVE-2026-76794
was published
Aug 28, 2026
The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector...
Moderate
Unreviewed
CVE-2026-76798
was published
Aug 28, 2026
WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event...
Moderate
Unreviewed
CVE-2026-39071
was published
Aug 28, 2026
Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before...
Moderate
Unreviewed
CVE-2026-50980
was published
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API