GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
152 advisories
Filter by severity
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary...
Critical
Unreviewed
CVE-2026-19295
was published
Aug 29, 2026
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the...
Critical
Unreviewed
CVE-2026-75062
was published
Aug 26, 2026
senaite.core Vulnerable to Eval Injection and Missing Authorization
Critical
CVE-2026-54569
was published
for
senaite.core
(pip)
Aug 26, 2026
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in...
High
Unreviewed
CVE-2026-78136
was published
Aug 23, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
Critical
CVE-2026-61539
was published
for
xinference
(pip)
Aug 21, 2026
@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers...
High
Unreviewed
CVE-2026-76833
was published
Aug 20, 2026
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in...
Critical
Unreviewed
CVE-2026-74899
was published
Aug 17, 2026
Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to...
Moderate
Unreviewed
CVE-2026-74234
was published
Aug 17, 2026
A remote code execution vulnerability exists in Tenable Security Center's report generation...
Critical
Unreviewed
CVE-2026-19626
was published
Aug 14, 2026
Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that...
Critical
Unreviewed
CVE-2026-73602
was published
Aug 13, 2026
Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP...
Critical
Unreviewed
CVE-2026-73601
was published
Aug 13, 2026
NLTK vulnerable to Eval Injection via collocations CLI arguments
High
CVE-2025-71408
was published
for
nltk
(pip)
Jul 25, 2026
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the...
Critical
Unreviewed
CVE-2026-61511
was published
Jul 27, 2026
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an...
High
Unreviewed
CVE-2026-48962
was published
May 27, 2026
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
Critical
CVE-2026-69264
was published
for
flowise
(npm)
Aug 4, 2026
Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated...
High
Unreviewed
CVE-2026-67195
was published
Aug 4, 2026
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in...
Critical
Unreviewed
CVE-2026-48317
was published
Aug 4, 2026
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category...
Critical
Unreviewed
CVE-2026-39932
was published
Aug 3, 2026
Rancher vulnerable to command injection through unsanitized YAML parameter
Critical
CVE-2026-44939
was published
for
github.com/rancher/rancher
(Go)
Jul 1, 2026
SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for...
Critical
Unreviewed
CVE-2026-15971
was published
Jul 30, 2026
AWS Amplify Studio UI Component Properties Has an Input Validation Issue
Critical
CVE-2025-4318
was published
for
@aws-amplify/codegen-ui-react
(npm)
Jul 30, 2026
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
High
CVE-2026-55415
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
High
CVE-2026-45293
was published
for
wp-coding-standards/wpcs
(Composer)
Jul 28, 2026
Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR....
Critical
Unreviewed
CVE-2026-64193
was published
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API