GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
9,926 advisories
Filter by severity
A security vulnerability has been detected in dbgate up to 7.3.1. Affected by this vulnerability...
Moderate
Unreviewed
CVE-2026-101070
was published
Sep 28, 2026
A weakness has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of...
Moderate
Unreviewed
CVE-2026-101069
was published
Sep 28, 2026
A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function...
Moderate
Unreviewed
CVE-2026-101066
was published
Sep 28, 2026
A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the...
Moderate
Unreviewed
CVE-2026-101067
was published
Sep 28, 2026
A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function...
Moderate
Unreviewed
CVE-2026-101068
was published
Sep 28, 2026
A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp...
Moderate
Unreviewed
CVE-2026-19444
was published
Sep 28, 2026
A vulnerability has been found in FLB-Music FLB-Music-Player 1.1.8/1.1.9/1.2.0/1.2.1. This...
Low
Unreviewed
CVE-2026-101036
was published
Sep 28, 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2026-82915
was published
Sep 28, 2026
Cloudreve before 4.16.1 fails to properly sanitize file paths returned by remote downloaders,...
Low
Unreviewed
CVE-2026-101051
was published
Sep 27, 2026
pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0...
High
Unreviewed
CVE-2026-101044
was published
Sep 27, 2026
Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in...
High
Unreviewed
CVE-2026-97164
was published
Sep 27, 2026
The WebFacing™ WordPress plugin before 5.4 does not restrict access to one of its bundled...
Moderate
Unreviewed
CVE-2026-84069
was published
Sep 27, 2026
Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin...
Critical
Unreviewed
CVE-2026-97161
was published
Sep 26, 2026
Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5...
Critical
Unreviewed
CVE-2026-97163
was published
Sep 26, 2026
Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of...
High
Unreviewed
CVE-2026-100707
was published
Sep 26, 2026
GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules...
High
Unreviewed
CVE-2026-100689
was published
Sep 26, 2026
Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon...
High
Unreviewed
CVE-2026-100682
was published
Sep 26, 2026
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML...
High
Unreviewed
CVE-2026-100636
was published
Sep 26, 2026
OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message...
High
Unreviewed
CVE-2026-100536
was published
Sep 26, 2026
OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice...
Moderate
Unreviewed
CVE-2026-100549
was published
Sep 26, 2026
OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs...
Moderate
Unreviewed
CVE-2026-100533
was published
Sep 26, 2026
Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager...
High
Unreviewed
CVE-2026-100520
was published
Sep 26, 2026
khoj has an unauthenticated path traversal in /home/ endpoint that allows file read from server filesystem
High
GHSA-62mm-xwmv-crhg
was published
for
khoj
(pip)
Sep 25, 2026
ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template...
High
Unreviewed
CVE-2026-100372
was published
Sep 25, 2026
Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary .md file read, write, and deletion in MCP Docs + Memory Tools
High
CVE-2026-86439
was published
for
knowns
(npm)
Sep 25, 2026
ProTip!
Advisories are also available from the
GraphQL API