GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
42
Go
3,114
Maven
5,000+
npm
5,000+
NuGet
826
pip
4,428
Pub
12
RubyGems
988
Rust
1,171
Swift
50
Unreviewed advisories
All unreviewed
5,000+
28,966 advisories
Filter by severity
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command...
Critical
Unreviewed
CVE-2026-25070
was published
Mar 7, 2026
OneUptime: Synthetic Monitor RCE via exposed Playwright browser object
Critical
GHSA-4j36-39gm-8vq8
was published
for
@oneuptime/common
(npm)
Mar 7, 2026
OneUpTime's Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCE
Critical
GHSA-h343-gg57-2q67
was published
for
@oneuptime/common
(npm)
Mar 7, 2026
SiYuan Vulnerable to Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakage
Critical
GHSA-2h2p-mvfx-868w
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 7, 2026
WeKnora has Remote Code Execution (RCE) via Command Injection in MCP Stdio Configuration Validation
Critical
CVE-2026-30861
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 7, 2026
WeKnora Vulnerable to Remote Code Execution via SQL Injection Bypass in AI Database Query Tool
Critical
CVE-2026-30860
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 6, 2026
WeKnora Vulnerable to Broken Access Control in Tenant Management
Critical
CVE-2026-30855
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 6, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import
Critical
CVE-2026-30832
was published
for
github.com/charmbracelet/soft-serve
(Go)
Mar 6, 2026
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform...
Critical
Unreviewed
CVE-2026-26288
was published
Mar 6, 2026
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform...
Critical
Unreviewed
CVE-2026-26051
was published
Mar 6, 2026
An attacker may access restricted filesystem areas on the device via the CROWN REST interface due...
Critical
Unreviewed
CVE-2026-2330
was published
Mar 6, 2026
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas...
Critical
Unreviewed
CVE-2026-2331
was published
Mar 6, 2026
The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF...
Critical
Unreviewed
CVE-2026-2446
was published
Mar 6, 2026
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform...
Critical
Unreviewed
CVE-2026-22552
was published
Mar 6, 2026
Microsoft Devices Pricing Program Remote Code Execution Vulnerability
Critical
Unreviewed
CVE-2026-21536
was published
Mar 6, 2026
NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation...
Critical
Unreviewed
CVE-2026-0848
was published
Mar 5, 2026
An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc...
Critical
Unreviewed
CVE-2025-29165
was published
Mar 5, 2026
An unsafe parsing of OpenMQ's configuration, allows a remote attacker to read arbitrary files...
Critical
Unreviewed
CVE-2026-24457
was published
Mar 5, 2026
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform...
Critical
Unreviewed
CVE-2025-70229
was published
Mar 5, 2026
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform...
Critical
Unreviewed
CVE-2025-70233
was published
Mar 5, 2026
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform...
Critical
Unreviewed
CVE-2025-70230
was published
Mar 5, 2026
D-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST...
Critical
Unreviewed
CVE-2025-70231
was published
Mar 5, 2026
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform...
Critical
Unreviewed
CVE-2025-70232
was published
Mar 5, 2026
Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and...
Critical
Unreviewed
CVE-2025-13476
was published
Mar 5, 2026
`time-sync` was removed from crates.io due to malicious code
Critical
GHSA-mh23-rw7f-v5pq
was published
for
time-sync
(Rust)
Mar 5, 2026
ProTip!
Advisories are also available from the
GraphQL API