GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,598
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
34,201 advisories
Filter by severity
disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access...
Critical
Unreviewed
CVE-2026-75338
was published
Aug 27, 2026
Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService...
Critical
Unreviewed
CVE-2026-75332
was published
Aug 27, 2026
The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond...
Critical
Unreviewed
CVE-2026-75330
was published
Aug 27, 2026
Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select...
Critical
Unreviewed
CVE-2026-75336
was published
Aug 27, 2026
The device metadata import interface /device/instance/{productId}/property-metadata/import of...
Critical
Unreviewed
CVE-2026-75340
was published
Aug 27, 2026
The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no...
Critical
Unreviewed
CVE-2026-75329
was published
Aug 27, 2026
A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from...
Critical
Unreviewed
CVE-2026-65641
was published
Aug 27, 2026
An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist...
Critical
Unreviewed
CVE-2025-51679
was published
Aug 26, 2026
Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on...
Critical
Unreviewed
CVE-2026-26448
was published
Aug 26, 2026
An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the...
Critical
Unreviewed
CVE-2025-70290
was published
Aug 26, 2026
DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '...
Critical
Unreviewed
CVE-2026-75325
was published
Aug 26, 2026
An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src...
Critical
Unreviewed
CVE-2026-51106
was published
Aug 26, 2026
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of...
Critical
Unreviewed
CVE-2026-70419
was published
Aug 26, 2026
A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI...
Critical
Unreviewed
CVE-2026-19485
was published
Aug 26, 2026
Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with...
Critical
Unreviewed
CVE-2025-61163
was published
Aug 26, 2026
An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North...
Critical
Unreviewed
CVE-2025-61165
was published
Aug 26, 2026
An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud...
Critical
Unreviewed
CVE-2026-12717
was published
Aug 26, 2026
ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel...
Critical
Unreviewed
CVE-2026-80428
was published
Aug 26, 2026
NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon...
Critical
Unreviewed
CVE-2026-81032
was published
Aug 26, 2026
Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research...
Critical
Unreviewed
CVE-2026-75896
was published
Aug 26, 2026
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the...
Critical
Unreviewed
CVE-2026-75062
was published
Aug 26, 2026
The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and...
Critical
Unreviewed
CVE-2026-18431
was published
Aug 26, 2026
EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability....
Critical
Unreviewed
CVE-2026-80235
was published
Aug 26, 2026
A malicious actor with access to the network and low privileges could exploit an Improper Input...
Critical
Unreviewed
CVE-2026-77533
was published
Aug 26, 2026
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is...
Critical
Unreviewed
CVE-2026-18080
was published
Aug 26, 2026
ProTip!
Advisories are also available from the
GraphQL API