GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,535
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,515
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
34,533 advisories
Filter by severity
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
Moderate
CVE-2026-73974
was published
for
linuxfabrik-lib
(pip)
Aug 18, 2026
moby/go-archive: Crafted tar archive can write outside the extraction directory
High
CVE-2026-17106
was published
for
github.com/moby/go-archive
(Go)
Aug 18, 2026
LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page
High
GHSA-7gww-x7fh-jf9j
was published
for
librenms/librenms
(Composer)
Aug 18, 2026
LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users
Moderate
GHSA-7cj5-v4pp-v632
was published
for
librenms/librenms
(Composer)
Aug 18, 2026
LibreNMS Vulnerable to Remote Code Execution via AboutController
Moderate
GHSA-jf24-8g2h-2wg7
was published
for
librenms/librenms
(Composer)
Aug 18, 2026
Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
High
CVE-2026-71417
was published
for
lemur
(pip)
Aug 18, 2026
Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
Moderate
CVE-2026-71322
was published
for
lemur
(pip)
Aug 18, 2026
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
Moderate
CVE-2026-71317
was published
for
lemur
(pip)
Aug 18, 2026
Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates
High
CVE-2026-71308
was published
for
lemur
(pip)
Aug 18, 2026
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
High
CVE-2026-71307
was published
for
lemur
(pip)
Aug 18, 2026
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
High
CVE-2026-71303
was published
for
lemur
(pip)
Aug 18, 2026
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
Moderate
CVE-2026-70667
was published
for
lemur
(pip)
Aug 18, 2026
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
High
CVE-2026-70666
was published
for
lemur
(pip)
Aug 18, 2026
Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints
Critical
CVE-2026-62988
was published
for
froxlor/froxlor
(Composer)
Aug 18, 2026
Froxlor has CSRF Vulnerability in AJAX Endpoint — Missing Cross-Site Request Forgery Protection
Moderate
CVE-2026-55593
was published
for
froxlor/froxlor
(Composer)
Aug 18, 2026
Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields
Moderate
CVE-2026-54543
was published
for
froxlor/froxlor
(Composer)
Aug 18, 2026
Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltration
High
CVE-2026-54348
was published
for
froxlor/froxlor
(Composer)
Aug 18, 2026
Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover
High
CVE-2026-54347
was published
for
froxlor/froxlor
(Composer)
Aug 18, 2026
devpi-server may leak database contents
Moderate
CVE-2026-54723
was published
for
devpi-server
(pip)
Aug 18, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
CVE-2026-55224
was published
for
mineadmin/mineadmin
(Composer)
Aug 18, 2026
MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files
High
GHSA-wg9g-w2j2-8pgr
was published
for
monai
(pip)
Aug 18, 2026
MONAI vulnerable to OS command injection
High
GHSA-rghg-q7wp-9767
was published
for
MONAI
(pip)
Aug 18, 2026
Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch
High
GHSA-qxq5-qhx6-94qw
was published
for
monai
(pip)
Aug 18, 2026
Triton VM Soundness Vulnerability due to Missing Constraint
Moderate
GHSA-vjf8-9fx6-mv6x
was published
for
triton-vm
(Rust)
Aug 18, 2026
jmespath.php has CompilerRuntime code injection via unescaped function names
Critical
CVE-2026-54133
was published
for
mtdowling/jmespath.php
(Composer)
Aug 18, 2026
ProTip!
Advisories are also available from the
GraphQL API