GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,839
Maven
5,000+
npm
4,467
NuGet
776
pip
4,228
Pub
12
RubyGems
973
Rust
1,093
Swift
47
Unreviewed advisories
All unreviewed
5,000+
300 advisories
Filter by severity
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
Critical
CVE-2025-68924
was published
for
UmbracoForms
(NuGet)
Jan 13, 2026
Crawl4AI is Vulnerable to Remote Code Execution in Docker API via Hooks Parameter
Critical
GHSA-5882-5rx9-xgxp
was published
for
Crawl4AI
(pip)
Jan 16, 2026
enclave-vm Vulnerable to Sandbox Escape via Host Error Prototype Chain
Critical
CVE-2026-22686
was published
for
enclave-vm
(npm)
Jan 14, 2026
Spree has Remote Command Execution vulnerability in search functionality
Critical
CVE-2011-10019
was published
for
spree
(RubyGems)
Aug 13, 2025
MineAdmin has an insecure default password
Critical
CVE-2025-65854
was published
for
mineadmin/mineadmin
(Composer)
Dec 12, 2025
pgadmin4 has a Meta-Command Filter Command Execution
Critical
CVE-2025-13780
was published
for
pgadmin4
(pip)
Dec 11, 2025
@vitejs/plugin-rsc Remote Code Execution through unsafe dynamic imports in RSC server function APIs on development server
Critical
CVE-2025-67489
was published
for
@vitejs/plugin-rsc
(npm)
Dec 8, 2025
Spree Commerce is vulnerable to RCE through Search API
Critical
CVE-2011-10026
was published
for
rd_searchlogic
(RubyGems)
Aug 20, 2025
Ray is vulnerable to Critical RCE via Safari & Firefox Browsers through DNS Rebinding Attack
Critical
CVE-2025-62593
was published
for
ray
(pip)
Nov 26, 2025
md-to-pdf vulnerable to arbitrary JavaScript code execution when parsing front matter
Critical
CVE-2025-65108
was published
for
md-to-pdf
(npm)
Nov 20, 2025
pgAdmin4 vulnerable to Remote Code Execution (RCE) when running in server mode
Critical
CVE-2025-12762
was published
for
pgadmin4
(pip)
Nov 13, 2025
Apache Zeppelin remote code execution by adding malicious JDBC connection string
Critical
CVE-2024-31864
was published
for
org.apache.zeppelin:zeppelin-jdbc
(Maven)
Apr 9, 2024
GitPython vulnerable to Remote Code Execution due to improper user input validation
Critical
CVE-2022-24439
was published
for
GitPython
(pip)
Dec 6, 2022
Arbitrary Code Execution in underscore
Critical
CVE-2021-23358
was published
for
underscore
(npm)
May 6, 2021
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
Critical
CVE-2020-13756
was published
for
sabberworm/php-css-parser
(Composer)
Mar 26, 2022
graphql allows remote code execution when loading a crafted GraphQL schema
Critical
CVE-2025-27407
was published
for
graphql
(RubyGems)
Mar 12, 2025
XWiki Platform allows remote code execution as guest via SolrSearchMacros request
Critical
CVE-2025-24893
was published
for
org.xwiki.platform:xwiki-platform-search-solr-ui
(Maven)
Feb 20, 2025
Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning
Critical
CVE-2025-59823
was published
for
github.com/gardener/gardener-extension-provider-aws
(Go)
Sep 25, 2025
Apache Struts Remote Java Code Execution
Critical
CVE-2012-0391
was published
for
org.apache.struts.xwork:xwork-core
(Maven)
May 4, 2022
Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabled
Critical
CVE-2024-56145
was published
for
craftcms/cms
(Composer)
Dec 18, 2024
Remote Code Execution (RCE) vulnerability in geoserver
Critical
CVE-2024-36401
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jul 1, 2024
Apache RocketMQ may have remote code execution vulnerability when using update configuration function
Critical
CVE-2023-33246
was published
for
org.apache.rocketmq:rocketmq-broker
(Maven)
Jul 6, 2023
Remote Code Execution in Spring Framework
Critical
CVE-2022-22965
was published
for
org.springframework.boot:spring-boot-starter-web
(Maven)
Mar 31, 2022
ProTip!
Advisories are also available from the
GraphQL API