GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
9,926 advisories
Filter by severity
IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to traverse directories on the...
Moderate
Unreviewed
CVE-2026-6925
was published
Sep 23, 2026
Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.
Moderate
Unreviewed
CVE-2026-95525
was published
Sep 23, 2026
Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking...
High
Unreviewed
CVE-2026-96651
was published
Sep 23, 2026
CyberPanel v1.9.1 contains a path traversal vulnerability in the compress method exposed through...
Moderate
Unreviewed
CVE-2026-79306
was published
Sep 23, 2026
CyberPanel 1.9.1 contains a path traversal vulnerability in the readFileContents method of the ...
Moderate
Unreviewed
CVE-2026-79304
was published
Sep 23, 2026
RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS...
Moderate
Unreviewed
CVE-2026-73102
was published
Sep 23, 2026
A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF...
High
Unreviewed
CVE-2026-91801
was published
Sep 23, 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2026-19438
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to...
Moderate
Unreviewed
CVE-2026-18114
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated...
Critical
Unreviewed
CVE-2026-18169
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated...
Moderate
Unreviewed
CVE-2026-18133
was published
Sep 23, 2026
An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact...
High
Unreviewed
CVE-2026-88344
was published
Sep 22, 2026
Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to...
Critical
Unreviewed
CVE-2026-88624
was published
Sep 22, 2026
Adobe Connect is affected by an Improper Limitation of a Pathname to a Restricted Directory (...
High
Unreviewed
CVE-2026-34689
was published
Sep 22, 2026
KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join
High
CVE-2026-62369
was published
for
github.com/kubeedge/kubeedge
(Go)
Sep 22, 2026
MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()
High
CVE-2026-77258
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4)
High
CVE-2026-77271
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)
High
CVE-2026-77262
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials
High
CVE-2026-77259
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary File Read via Upload Attachment Tools
Moderate
CVE-2026-77270
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call
Moderate
CVE-2026-77266
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)
Moderate
CVE-2026-77269
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)
High
CVE-2026-77260
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths
High
CVE-2026-77257
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue
High
CVE-2026-77255
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
ProTip!
Advisories are also available from the
GraphQL API