GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
4,105 advisories
Filter by severity
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
Moderate
GHSA-p23f-cm6q-2qp8
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 2, 2026
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path
Moderate
CVE-2026-59944
was published
for
composer/composer
(Composer)
Oct 2, 2026
Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module)...
Moderate
Unreviewed
CVE-2026-104721
was published
Oct 2, 2026
Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file...
Moderate
Unreviewed
CVE-2026-104417
was published
Oct 2, 2026
A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution...
Moderate
Unreviewed
CVE-2026-103884
was published
Oct 1, 2026
vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
Moderate
CVE-2026-92945
was published
for
vm2
(npm)
Oct 1, 2026
A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a...
Moderate
Unreviewed
CVE-2026-103754
was published
Oct 1, 2026
A path traversal vulnerability exists in the web management interface of multiple Multifunction...
Moderate
Unreviewed
CVE-2026-78249
was published
Oct 1, 2026
A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity...
Moderate
Unreviewed
CVE-2026-76147
was published
Oct 1, 2026
GitPython submodule update path traversal can write outside the repository
Moderate
GHSA-59cr-6r3x-644w
was published
for
GitPython
(pip)
Sep 30, 2026
Author Arbitrary File Deletion in WEBO MCP <= 3.0.18 versions.
Moderate
Unreviewed
CVE-2026-97242
was published
Sep 30, 2026
Editor Arbitrary File Deletion in Template Kit – Import <= 1.0.16 versions.
Moderate
Unreviewed
CVE-2026-96824
was published
Sep 30, 2026
An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an...
Moderate
Unreviewed
CVE-2026-86105
was published
Sep 30, 2026
mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper...
Moderate
Unreviewed
CVE-2026-79534
was published
Sep 29, 2026
A path traversal vulnerability (CWE-22) in the embedded VMDK filesystem extractor in Google OSV...
Moderate
Unreviewed
CVE-2026-102252
was published
Sep 29, 2026
Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final...
Moderate
Unreviewed
CVE-2026-101126
was published
Sep 29, 2026
Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service and possible...
Moderate
Unreviewed
CVE-2026-96419
was published
Sep 29, 2026
Dozzle versions before 11.1.2 fail to sanitize container display names when building ZIP archive...
Moderate
Unreviewed
CVE-2026-102332
was published
Sep 29, 2026
A weakness has been identified in PMWeb 7.x/8.x/2025.x. This issue affects some unknown...
Moderate
Unreviewed
CVE-2026-101082
was published
Sep 28, 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2026-15953
was published
Sep 28, 2026
A security vulnerability has been detected in dbgate up to 7.3.1. Affected by this vulnerability...
Moderate
Unreviewed
CVE-2026-101070
was published
Sep 28, 2026
A weakness has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of...
Moderate
Unreviewed
CVE-2026-101069
was published
Sep 28, 2026
A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function...
Moderate
Unreviewed
CVE-2026-101066
was published
Sep 28, 2026
A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the...
Moderate
Unreviewed
CVE-2026-101067
was published
Sep 28, 2026
A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function...
Moderate
Unreviewed
CVE-2026-101068
was published
Sep 28, 2026
ProTip!
Advisories are also available from the
GraphQL API