GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,582
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
34,156 advisories
Filter by severity
The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito...
Critical
Unreviewed
CVE-2026-81674
was published
Aug 27, 2026
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware...
Critical
Unreviewed
CVE-2026-74233
was published
Aug 27, 2026
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628...
Critical
Unreviewed
CVE-2026-74232
was published
Aug 27, 2026
Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
Critical
Unreviewed
CVE-2026-78260
was published
Aug 27, 2026
Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
Critical
Unreviewed
CVE-2026-78274
was published
Aug 27, 2026
Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
Critical
Unreviewed
CVE-2026-78288
was published
Aug 27, 2026
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
Critical
Unreviewed
CVE-2026-78286
was published
Aug 27, 2026
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
Critical
Unreviewed
CVE-2026-78292
was published
Aug 27, 2026
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2...
Critical
Unreviewed
CVE-2026-32566
was published
Aug 27, 2026
Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
Critical
Unreviewed
CVE-2026-32479
was published
Aug 27, 2026
Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event...
Critical
Unreviewed
CVE-2026-77991
was published
Aug 27, 2026
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers...
Critical
Unreviewed
CVE-2026-59270
was published
Aug 27, 2026
The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a...
Critical
Unreviewed
CVE-2026-77016
was published
Aug 27, 2026
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application...
Critical
Unreviewed
CVE-2026-47884
was published
Aug 27, 2026
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not...
Critical
Unreviewed
CVE-2026-47891
was published
Aug 27, 2026
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent...
Critical
Unreviewed
CVE-2026-47890
was published
Aug 27, 2026
In the Linux kernel, the following vulnerability has been resolved:
mptcp: fastopen: only mark...
Critical
Unreviewed
CVE-2026-80585
was published
Aug 27, 2026
In the Linux kernel, the following vulnerability has been resolved:
mptcp: options: reset DSS...
Critical
Unreviewed
CVE-2026-80586
was published
Aug 27, 2026
In the Linux kernel, the following vulnerability has been resolved:
block: stop the timeout...
Critical
Unreviewed
CVE-2026-80589
was published
Aug 27, 2026
In the Linux kernel, the following vulnerability has been resolved:
mptcp: avoid combining some...
Critical
Unreviewed
CVE-2026-80587
was published
Aug 27, 2026
In the Linux kernel, the following vulnerability has been resolved:
s390/vfio_ccw: Limit the...
Critical
Unreviewed
CVE-2026-80554
was published
Aug 27, 2026
In the Linux kernel, the following vulnerability has been resolved:
libceph: Avoid using invalid...
Critical
Unreviewed
CVE-2026-80558
was published
Aug 27, 2026
In the Linux kernel, the following vulnerability has been resolved:
libceph: fix multiple unsafe...
Critical
Unreviewed
CVE-2026-80561
was published
Aug 27, 2026
In the Linux kernel, the following vulnerability has been resolved:
libceph: fix OOB read in...
Critical
Unreviewed
CVE-2026-80557
was published
Aug 27, 2026
In the Linux kernel, the following vulnerability has been resolved:
s390/vfio_ccw: Ensure first...
Critical
Unreviewed
CVE-2026-80551
was published
Aug 27, 2026
ProTip!
Advisories are also available from the
GraphQL API