GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
174,280 advisories
Filter by severity
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &...
Moderate
Unreviewed
CVE-2026-92551
was published
Oct 3, 2026
The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed...
Moderate
Unreviewed
CVE-2026-92727
was published
Oct 3, 2026
The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross...
Moderate
Unreviewed
CVE-2026-92243
was published
Oct 3, 2026
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-95865
was published
Oct 3, 2026
The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-94378
was published
Oct 3, 2026
The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-94539
was published
Oct 3, 2026
The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress...
Moderate
Unreviewed
CVE-2026-100180
was published
Oct 3, 2026
Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head...
Moderate
Unreviewed
CVE-2026-105090
was published
Oct 3, 2026
OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow.
Moderate
Unreviewed
CVE-2026-79113
was published
Oct 3, 2026
Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and...
Moderate
Unreviewed
CVE-2026-104477
was published
Oct 3, 2026
Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self...
Moderate
Unreviewed
CVE-2026-104479
was published
Oct 3, 2026
UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference...
Moderate
Unreviewed
CVE-2026-105029
was published
Oct 3, 2026
Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows...
Moderate
Unreviewed
CVE-2026-105030
was published
Oct 3, 2026
OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup...
Moderate
Unreviewed
CVE-2026-104474
was published
Oct 3, 2026
IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows...
Moderate
Unreviewed
CVE-2026-104475
was published
Oct 3, 2026
Armatura One's message broker logs client connection credentials and the associated password in...
Moderate
Unreviewed
CVE-2026-94594
was published
Oct 3, 2026
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows...
Moderate
Unreviewed
CVE-2026-97212
was published
Oct 3, 2026
The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private...
Moderate
Unreviewed
CVE-2026-105048
was published
Oct 3, 2026
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Moderate
Unreviewed
CVE-2026-93474
was published
Oct 3, 2026
Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for...
Moderate
Unreviewed
CVE-2026-105049
was published
Oct 3, 2026
Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration...
Moderate
Unreviewed
CVE-2026-105046
was published
Oct 3, 2026
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
Moderate
GHSA-p23f-cm6q-2qp8
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 2, 2026
sqlite3-ruby: Use-After-Free in SQLite Aggregate Arguments in Heap-Allocated Argument Array
Moderate
GHSA-mwm8-39rw-8826
was published
for
sqlite3
(RubyGems)
Oct 2, 2026
Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values
Moderate
GHSA-fj2x-mqqp-3v2w
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Cross-environment deployment cancel
Moderate
GHSA-4672-hwv6-gq62
was published
for
trigger.dev
(npm)
Oct 2, 2026
ProTip!
Advisories are also available from the
GraphQL API