GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
48
GitHub Actions
48
Go
3,391
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,614
Pub
13
RubyGems
1,026
Rust
1,205
Swift
51
Unreviewed advisories
All unreviewed
5,000+
29,432 advisories
Filter by severity
fast-jwt: Incomplete fix for CVE-2023-48223: JWT Algorithm Confusion via Whitespace-Prefixed RSA Public Key
Critical
CVE-2026-34950
was published
for
fast-jwt
(npm)
Apr 2, 2026
Axios supply chain attack - dependency in @lightdash/cli may resolve to compromised axios versions
Critical
GHSA-3hfp-gqgh-xc5g
was published
for
@lightdash/cli
(npm)
Apr 2, 2026
Axios npm Supply Chain Incident Impacting @usebruno/cli
Critical
CVE-2026-34841
was published
for
@usebruno/cli
(npm)
Apr 2, 2026
An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while...
Critical
Unreviewed
CVE-2026-34873
was published
Apr 1, 2026
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in...
Critical
Unreviewed
CVE-2026-34714
was published
Mar 30, 2026
An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0....
Critical
Unreviewed
CVE-2026-34877
was published
Apr 2, 2026
An issue was discovered in Percona PMM before 3.7. Because an internal database user retains...
Critical
Unreviewed
CVE-2026-25212
was published
Apr 2, 2026
An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows...
Critical
Unreviewed
CVE-2026-30285
was published
Mar 31, 2026
An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows...
Critical
Unreviewed
CVE-2026-30286
was published
Mar 31, 2026
An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3...
Critical
Unreviewed
CVE-2026-30283
was published
Mar 31, 2026
An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows...
Critical
Unreviewed
CVE-2026-30278
was published
Mar 31, 2026
In the Linux kernel, the following vulnerability has been resolved:
tls: Fix race condition in...
Critical
Unreviewed
CVE-2026-23240
was published
Mar 10, 2026
Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model...
Critical
Unreviewed
CVE-2026-35002
was published
Apr 2, 2026
Authenticated user can upload a malicious file to the server and execute it, which leads to...
Critical
Unreviewed
CVE-2026-2701
was published
Apr 2, 2026
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to...
Critical
Unreviewed
CVE-2026-2699
was published
Apr 2, 2026
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in...
Critical
Unreviewed
CVE-2026-33615
was published
Apr 2, 2026
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: ipc: fix use-after...
Critical
Unreviewed
CVE-2025-68263
was published
Dec 16, 2025
Juju has Improper TLS Client/Server authentication and certificate verification on Database Cluster
Critical
CVE-2026-4370
was published
for
github.com/juju/juju
(Go)
Apr 2, 2026
PraisonAI Has Authentication Bypass via OAuthManager.validate_token()
Critical
CVE-2026-34953
was published
for
praisonai
(pip)
Apr 1, 2026
PraisonAI Has Missing Authentication in WebSocket Gateway
Critical
CVE-2026-34952
was published
for
praisonai
(pip)
Apr 1, 2026
PraisonAI Has Second-Order SQL Injection in `get_all_user_threads`
Critical
CVE-2026-34934
was published
for
praisonai
(pip)
Apr 1, 2026
PraisonAI: OS Command Injection in MCPHandler.parse_mcp_command()
Critical
CVE-2026-34935
was published
for
praisonai
(pip)
Apr 1, 2026
PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code
Critical
CVE-2026-34938
was published
for
praisonaiagents
(pip)
Apr 1, 2026
CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise
Critical
CVE-2026-34571
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 1, 2026
CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
CVE-2026-34569
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 1, 2026
ProTip!
Advisories are also available from the
GraphQL API