GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
34,180 advisories
Filter by severity
Electron: window.open features string controls some window options considered privileged
Moderate
CVE-2026-70607
was published
for
electron
(npm)
Aug 5, 2026
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
Moderate
CVE-2026-70606
was published
for
electron
(npm)
Aug 5, 2026
Electron: HTTP redirect followed into local file loader
Moderate
CVE-2026-70605
was published
for
electron
(npm)
Aug 5, 2026
Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
High
CVE-2026-70604
was published
for
electron
(npm)
Aug 5, 2026
Electron: Extension tab APIs operate across session boundaries
Moderate
CVE-2026-70602
was published
for
electron
(npm)
Aug 5, 2026
Electron: shell.openPath path validation bypass via embedded null byte
Moderate
CVE-2026-70603
was published
for
electron
(npm)
Aug 5, 2026
Electron: Context isolation bypass via Function.prototype.bind hijack
High
CVE-2026-70601
was published
for
electron
(npm)
Aug 5, 2026
Electron: Cross-origin iframe can position native autofill popup
Low
CVE-2026-70600
was published
for
electron
(npm)
Aug 5, 2026
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
Moderate
CVE-2026-70599
was published
for
electron
(npm)
Aug 5, 2026
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
Low
CVE-2026-70598
was published
for
electron
(npm)
Aug 5, 2026
Electron: Parent process code-sign check is spoofable
Moderate
CVE-2026-70597
was published
for
electron
(npm)
Aug 5, 2026
Ghost Content API filter bypass reveals private fields
Moderate
CVE-2026-53949
was published
for
ghost
(npm)
Aug 5, 2026
Ghost: Cross-Site Scripting in Feature Image Captions
Moderate
CVE-2026-70596
was published
for
ghost
(npm)
Aug 5, 2026
Ghost: Server-Side Request Forgery Mitigation Issue
Moderate
CVE-2026-70595
was published
for
ghost
(npm)
Aug 5, 2026
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
Moderate
CVE-2026-59817
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Member existence leak via magic link sign-in response
Moderate
CVE-2026-53947
was published
for
ghost
(npm)
Aug 4, 2026
XSS in Ghost's ActivityPub client
High
CVE-2026-53950
was published
for
@tryghost/activitypub
(npm)
Aug 4, 2026
Ghost: Session Fixation in Ghost Admin
Moderate
CVE-2026-70594
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Theme Upload Path Traversal
Moderate
CVE-2026-70593
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Database Backup Path Traversal
Moderate
CVE-2026-70592
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Server-Side Request Forgery in Image Fetching
Moderate
CVE-2026-70591
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Blind Password Hash Disclosure in Ghost Admin API
Moderate
CVE-2026-70590
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Mobiledoc image-size fetch SSRF
Moderate
CVE-2026-53946
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Server-side request forgery via DNS rebinding in external request handling
Moderate
CVE-2026-53945
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Private IP filtering bypass to make server-side requests to internal services
Moderate
CVE-2026-53944
was published
for
ghost
(npm)
Aug 4, 2026
ProTip!
Advisories are also available from the
GraphQL API