GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
133,099 advisories
Filter by severity
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in...
High
Unreviewed
CVE-2026-15962
was published
Jul 26, 2026
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to...
High
Unreviewed
CVE-2026-10818
was published
Jul 25, 2026
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE,...
High
Unreviewed
CVE-2026-66373
was published
Jul 25, 2026
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the...
High
Unreviewed
CVE-2026-66374
was published
Jul 25, 2026
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
High
Unreviewed
CVE-2026-61892
was published
Jul 25, 2026
Weintek cMT3092X HMI stores user account passwords in plaintext.
High
Unreviewed
CVE-2026-61886
was published
Jul 25, 2026
An attacker can modify data that should be restricted to read‑only access.
High
Unreviewed
CVE-2026-60135
was published
Jul 25, 2026
Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
High
Unreviewed
CVE-2026-60134
was published
Jul 25, 2026
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in...
High
Unreviewed
CVE-2025-71408
was published
Jul 25, 2026
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
High
GHSA-6vch-q96h-7gc3
was published
for
go.etcd.io/etcd/v3
(Go)
Jul 24, 2026
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
High
CVE-2026-16796
was published
for
bedrock-agentcore
(pip)
Jul 24, 2026
etcd: Watch API authorization bypass via open-ended range requests
High
GHSA-xg4h-6gfc-h4m8
was published
for
go.etcd.io/etcd/v3
(Go)
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
CVE-2026-16756
was published
for
aws-smithy-http-server
(Rust)
Jul 24, 2026
libp2p: yamux connection DoS via oversized data frame
High
GHSA-hmj8-5xmh-5573
was published
for
libp2p
(pip)
Jul 24, 2026
Oh My Posh: Arbitrary command execution via template injection in the path segment
High
GHSA-6xj8-qv9j-xcjq
was published
for
github.com/jandedobbeleer/oh-my-posh
(Go)
Jul 24, 2026
OmniFaces: Forged combined-resource IDs and related output/push boundaries
High
GHSA-fp43-vj7g-pg92
was published
for
org.omnifaces:omnifaces
(Maven)
Jul 24, 2026
Shescape: Quadratic-time denial of service in the flag-protection
High
GHSA-gm3r-q2wp-hw87
was published
for
shescape
(npm)
Jul 24, 2026
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
High
CVE-2026-16584
was published
for
awslabs.aws-api-mcp-server
(pip)
Jul 24, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
High
GHSA-95cv-r8x4-vh75
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
High
GHSA-7ppr-r889-mcf2
was published
for
org.http4s:http4s-blaze-server_2.12
(Maven)
Jul 24, 2026
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
High
GHSA-46q4-43ph-c6fr
was published
for
org.http4s:blaze-http_2.12
(Maven)
Jul 24, 2026
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
High
GHSA-mhvj-jhpq-885v
was published
for
org.http4s:blaze-http_2.13
(Maven)
Jul 24, 2026
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
High
GHSA-cmwh-g2h8-c222
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
High
GHSA-rm67-g9ch-vxff
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
High
GHSA-h4hf-v6w5-897x
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API