GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
43
Go
3,164
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,458
Pub
12
RubyGems
991
Rust
1,184
Swift
50
Unreviewed advisories
All unreviewed
5,000+
810 advisories
Filter by severity
SimpleEval: Objects (including modules) can leak dangerous modules through to direct access inside the sandbox
High
CVE-2026-32640
was published
for
simpleeval
(pip)
Mar 13, 2026
Locutus vulnerable to RCE via unsanitized input in create_function()
Critical
CVE-2026-32304
was published
for
locutus
(npm)
Mar 13, 2026
SandboxJS affected by a Sandbox Escape
Critical
CVE-2026-26954
was published
for
@nyariv/sandboxjs
(npm)
Mar 13, 2026
CraftCMS has an RCE vulnerability via relational conditionals in the control panel
High
CVE-2026-31857
was published
for
craftcms/cms
(Composer)
Mar 11, 2026
@siteboon/claude-code-ui is Vulnerable to Shell Command Injection in Git Routes
High
CVE-2026-31861
was published
for
@siteboon/claude-code-ui
(npm)
Mar 10, 2026
RSSN has Arbitrary Code Execution via Unvalidated JIT Instruction Generation in C-FFI Interface
Critical
CVE-2026-30960
was published
for
rssn
(Rust)
Mar 10, 2026
AzuraCast: RCE via Liquidsoap string interpolation injection in station metadata and playlist URLs
High
GHSA-93fx-5qgc-wr38
was published
for
azuracast/azuracast
(Composer)
Mar 9, 2026
OneUpTime's Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCE
Critical
CVE-2026-30887
was published
for
@oneuptime/common
(npm)
Mar 7, 2026
changedetection.io vulnerable to XPath - Arbitrary File Read via unparsed-text()
High
CVE-2026-29039
was published
for
changedetection.io
(pip)
Mar 4, 2026
OpenClaw hook transform path containment missed symlink-resolved escapes
High
GHSA-659f-22xc-98f2
was published
for
openclaw
(npm)
Mar 3, 2026
Craft CMS has Twig Function Blocklist Bypass
Moderate
CVE-2026-28783
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS Vulnerable to Authenticated RCE via Twig SSTI - create() function + Symfony Process gadget
Moderate
CVE-2026-28695
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Apache Ranger has a Code Injection vulnerability
Critical
CVE-2025-59059
was published
for
org.apache.ranger:ranger-plugins-common
(Maven)
Mar 3, 2026
Statamic vulnerable to remote code execution via Antlers-enabled control panel inputs
High
CVE-2026-28425
was published
for
statamic/cms
(Composer)
Mar 1, 2026
OpenClaw: Skill env override host env injection via applySkillConfigEnvOverrides (defense-in-depth)
Moderate
CVE-2026-4039
was published
for
openclaw
(npm)
Feb 27, 2026
Langflow has Remote Code Execution in CSV Agent
Critical
CVE-2026-27966
was published
for
langflow
(pip)
Feb 27, 2026
n8n: Expression Sandbox Escape Leads to RCE
Critical
CVE-2026-27577
was published
for
n8n
(npm)
Feb 25, 2026
n8n has Arbitrary Command Execution via File Write and Git Operations
Critical
CVE-2026-27498
was published
for
n8n
(npm)
Feb 25, 2026
n8n has Potential Remote Code Execution via Merge Node
Critical
CVE-2026-27497
was published
for
n8n
(npm)
Feb 25, 2026
n8n has a Sandbox Escape in its JavaScript Task Runner
Critical
CVE-2026-27495
was published
for
n8n
(npm)
Feb 25, 2026
n8n has Unauthenticated Expression Evaluation via Form Node
Critical
CVE-2026-27493
was published
for
n8n
(npm)
Feb 25, 2026
Budibase: Remote Code Execution via Unsafe eval() in View Filter Map Function (Budibase Cloud)
Critical
CVE-2026-27702
was published
for
budibase
(npm)
Feb 25, 2026
c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString property
High
CVE-2026-27830
was published
for
com.mchange:c3p0
(Maven)
Feb 25, 2026
@enclave-vm/core is vulnerable to Sandbox Escape
Critical
CVE-2026-27597
was published
for
@enclave-vm/core
(npm)
Feb 25, 2026
OneUptime:: node:vm sandbox escape in probe allows any project member to achieve RCE
Critical
CVE-2026-27574
was published
for
@oneuptime/common
(npm)
Feb 24, 2026
ProTip!
Advisories are also available from the
GraphQL API