GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
117
GitHub Actions
55
Go
4,836
Maven
5,000+
npm
5,000+
NuGet
1,126
pip
5,000+
Pub
13
RubyGems
1,157
Rust
1,577
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
35,542 advisories
Filter by severity
A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome...
Critical
Unreviewed
CVE-2026-84388
was published
Sep 22, 2026
webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session...
Critical
Unreviewed
CVE-2026-79313
was published
Sep 22, 2026
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause...
Critical
Unreviewed
CVE-2026-65113
was published
Sep 22, 2026
D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code...
Critical
Unreviewed
CVE-2026-95675
was published
Sep 22, 2026
Improper neutralization of special elements used in an SQL command ('SQL injection')...
Critical
Unreviewed
CVE-2026-12718
was published
Sep 22, 2026
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload...
Critical
Unreviewed
CVE-2026-93616
was published
Sep 22, 2026
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote...
Critical
Unreviewed
CVE-2026-74849
was published
Sep 22, 2026
Improper authorization leads to Remote Code Execution via SocketIO interface.
Critical
Unreviewed
CVE-2026-25254
was published
Sep 22, 2026
The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies...
Critical
Unreviewed
CVE-2026-93556
was published
Sep 22, 2026
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote...
Critical
Unreviewed
CVE-2026-93952
was published
Sep 22, 2026
Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every...
Critical
Unreviewed
CVE-2026-87078
was published
Sep 22, 2026
Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name...
Critical
Unreviewed
CVE-2026-87080
was published
Sep 22, 2026
Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked...
Critical
Unreviewed
CVE-2016-15059
was published
Sep 22, 2026
The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up...
Critical
Unreviewed
CVE-2026-19658
was published
Sep 22, 2026
The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in...
Critical
Unreviewed
CVE-2026-13355
was published
Sep 22, 2026
A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some...
Critical
Unreviewed
CVE-2026-94493
was published
Sep 22, 2026
A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element...
Critical
Unreviewed
CVE-2026-94425
was published
Sep 22, 2026
An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib...
Critical
Unreviewed
CVE-2026-78847
was published
Sep 22, 2026
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters...
Critical
Unreviewed
CVE-2026-94571
was published
Sep 21, 2026
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and...
Critical
Unreviewed
CVE-2026-94572
was published
Sep 21, 2026
A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is...
Critical
Unreviewed
CVE-2026-94424
was published
Sep 21, 2026
A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (...
Critical
Unreviewed
CVE-2026-88404
was published
Sep 21, 2026
A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to...
Critical
Unreviewed
CVE-2026-88402
was published
Sep 21, 2026
Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command...
Critical
Unreviewed
CVE-2026-93012
was published
Sep 21, 2026
Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token...
Critical
Unreviewed
CVE-2026-86473
was published
Sep 21, 2026
ProTip!
Advisories are also available from the
GraphQL API