GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,630
Maven
5,000+
npm
5,000+
NuGet
928
pip
4,850
Pub
13
RubyGems
1,045
Rust
1,301
Swift
53
Unreviewed advisories
All unreviewed
5,000+
437 advisories
Filter by severity
ERB has an @_init deserialization guard bypass via def_module / def_method / def_class
High
CVE-2026-41316
was published
for
erb
(RubyGems)
Apr 24, 2026
OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment
High
CVE-2026-41900
was published
for
openlearnx
(npm)
Apr 23, 2026
Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted...
Moderate
Unreviewed
CVE-2026-41469
was published
Apr 22, 2026
Spring Security Doesn't Correctly Include Servlet Path in Path Matching of HttpSecurity#securityMatchers
High
CVE-2026-22753
was published
for
org.springframework.security:spring-security-config
(Maven)
Apr 22, 2026
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...
Moderate
Unreviewed
CVE-2026-22013
was published
Apr 21, 2026
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150.
Moderate
Unreviewed
CVE-2026-6774
was published
Apr 21, 2026
Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150 and...
Moderate
Unreviewed
CVE-2026-6763
was published
Apr 21, 2026
NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] ...
Critical
Unreviewed
CVE-2026-29649
was published
Apr 20, 2026
OpenClaw: Browser interaction routes could pivot into local CDP and regain file reads
Moderate
GHSA-qmwg-qprg-3j38
was published
for
openclaw
(npm)
Apr 17, 2026
October Rain has a Twig Sandbox Bypass via Collection Methods
Moderate
CVE-2026-22692
was published
for
october/rain
(Composer)
Apr 14, 2026
ImageMagick has a heap-use-after-free via XMP profile could result in a crash when printing the values.
Moderate
CVE-2026-40311
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a...
High
Unreviewed
CVE-2026-32225
was published
Apr 14, 2026
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing...
Moderate
Unreviewed
CVE-2026-32202
was published
Apr 14, 2026
PraisonAI Vulnerable to Code Injection and Protection Mechanism Failure
High
CVE-2026-40158
was published
for
PraisonAI
(pip)
Apr 10, 2026
Policy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-5911
was published
Apr 9, 2026
Policy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to...
Moderate
Unreviewed
CVE-2026-5900
was published
Apr 9, 2026
Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-5903
was published
Apr 9, 2026
Policy bypass in Audio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who...
Moderate
Unreviewed
CVE-2026-5896
was published
Apr 9, 2026
PraisonAI has sandbox escape via exception frame traversal in `execute_code` (subprocess mode)
Critical
CVE-2026-39888
was published
for
praisonaiagents
(pip)
Apr 8, 2026
Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
High
CVE-2026-34444
was published
for
lupa
(pip)
Apr 7, 2026
Directus: Missing Cross-Origin Opener Policy
High
CVE-2026-35408
was published
for
directus
(npm)
Apr 4, 2026
SandboxJS: Sandbox integrity escape
Critical
CVE-2026-34208
was published
for
@nyariv/sandboxjs
(npm)
Apr 3, 2026
PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code
Critical
CVE-2026-34938
was published
for
praisonaiagents
(pip)
Apr 1, 2026
Insufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a...
Moderate
Unreviewed
CVE-2026-5276
was published
Apr 1, 2026
vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out
High
CVE-2026-27893
was published
for
vllm
(pip)
Mar 27, 2026
ProTip!
Advisories are also available from the
GraphQL API