GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
2,818
Erlang
23
GitHub Actions
38
Go
2,203
Maven
2,576
npm
2,819
NuGet
487
pip
2,656
Pub
5
RubyGems
328
Rust
877
Swift
19
Unreviewed advisories
All unreviewed
5,000+
149,730 advisories
Filter by severity
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
Moderate
GHSA-ffq5-qpvf-xq7x
was published
for
openc3
(RubyGems)
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
Moderate
GHSA-4jvx-93h3-f45h
was published
for
openc3
(RubyGems)
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
High
GHSA-wgx6-g857-jjf7
was published
for
openc3
(RubyGems)
Apr 22, 2026
OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle
Moderate
CVE-2026-41511
was published
for
OpenMcdf
(NuGet)
Apr 22, 2026
Evolver: Path Traversal via `--out` flag in `fetch` command allows Arbitrary File Write
High
GHSA-r466-rxw4-3j9j
was published
for
@evomap/evolver
(npm)
Apr 22, 2026
Evolver: Command Injection via `execSync` in `_extractLLM()` function allows Remote Code Execution
Critical
GHSA-j5w5-568x-rq53
was published
for
@evomap/evolver
(npm)
Apr 22, 2026
Evolver has Prototype Pollution via `Object.assign()` in its mailbox store operations
Moderate
GHSA-2cjr-5v3h-v2w4
was published
for
@evomap/evolver
(npm)
Apr 22, 2026
NornicDB has Improper Network Binding in its Bolt Server, allowing unauthorized remote access
Critical
GHSA-2hp7-65r3-wv54
was published
for
github.com/orneryd/nornicdb
(Go)
Apr 22, 2026
RAGAS has SSRF via Multi-Modal Faithfulness Collections Module
Low
CVE-2026-6587
was published
for
ragas
(pip)
Apr 20, 2026
If you use the zoneToCache function with a malicious authoritative server, an attacker can send a...
Moderate
Unreviewed
CVE-2026-33601
was published
Apr 22, 2026
Insufficient validation of Chrome extension identifiers in Raindrop.io Bookmark Manager Web App 5...
Moderate
Unreviewed
CVE-2026-31192
was published
Apr 22, 2026
A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0....
Moderate
Unreviewed
CVE-2026-26399
was published
Apr 20, 2026
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the...
Moderate
Unreviewed
CVE-2026-41254
was published
Apr 18, 2026
Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability...
Moderate
Unreviewed
CVE-2026-41459
was published
Apr 22, 2026
Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability...
High
Unreviewed
CVE-2026-34414
was published
Apr 22, 2026
Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted...
Moderate
Unreviewed
CVE-2026-41469
was published
Apr 22, 2026
Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation...
Critical
Unreviewed
CVE-2026-34415
was published
Apr 22, 2026
Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known...
Critical
Unreviewed
CVE-2026-41468
was published
Apr 22, 2026
Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in...
High
Unreviewed
CVE-2026-34413
was published
Apr 22, 2026
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for...
Low
Unreviewed
CVE-2026-6019
was published
Apr 22, 2026
An authenticated attacker can persist crafted values in multiple field types and trigger client...
Moderate
Unreviewed
CVE-2026-3837
was published
Apr 22, 2026
An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript...
Moderate
Unreviewed
CVE-2026-3673
was published
Apr 22, 2026
Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7...
High
Unreviewed
CVE-2026-26354
was published
Apr 22, 2026
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.8 and...
Unknown
Unreviewed
CVE-2026-28950
was published
Apr 22, 2026
An attacker can send a web request that causes unlimited memory allocation in the internal web...
Moderate
Unreviewed
CVE-2026-33260
was published
Apr 22, 2026
ProTip!
Advisories are also available from the
GraphQL API