GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
48
GitHub Actions
48
Go
3,391
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,614
Pub
13
RubyGems
1,013
Rust
1,205
Swift
51
Unreviewed advisories
All unreviewed
5,000+
10 advisories
Filter by severity
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`
Moderate
CVE-2026-2950
was published
for
lodash
(npm)
Apr 1, 2026
SillyTavern: Path Traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user data root
High
CVE-2026-34524
was published
for
sillytavern
(npm)
Apr 1, 2026
SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory
High
CVE-2026-34522
was published
for
sillytavern
(npm)
Apr 1, 2026
Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration
Moderate
CVE-2026-32828
was published
for
github.com/akuity/kargo
(Go)
Mar 16, 2026
Uncontrolled memory allocation via crafted SVG dimensions in @dicebear/converter
High
CVE-2026-29112
was published
for
@dicebear/converter
(npm)
Mar 16, 2026
OneUptime has Synthetic Monitor RCE via exposed Playwright browser object
Critical
CVE-2026-30957
was published
for
@oneuptime/common
(npm)
Mar 10, 2026
OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding
High
CVE-2026-30920
was published
for
@oneuptime/common
(npm)
Mar 9, 2026
OneUptime: Synthetic Monitor RCE via exposed Playwright browser object
Critical
CVE-2026-30921
was published
for
@oneuptime/common
(npm)
Mar 7, 2026
OliveTin has crash on NPE by calling APIs with invalid bindings or log references
Moderate
GHSA-fwhj-785h-43hh
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
SiYuan: Unauthenticated Reflected XSS via SVG Injection in /api/icon/getDynamicIcon Endpoint
Critical
CVE-2026-29183
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 4, 2026
ProTip!
Advisories are also available from the
GraphQL API