GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
141 advisories
Filter by severity
Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked...
Moderate
Unreviewed
CVE-2026-56706
was published
Aug 25, 2026
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling
Moderate
GHSA-92hr-gmr6-h8cp
was published
for
ep_etherpad-lite
(npm)
Aug 17, 2026
A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the...
Moderate
Unreviewed
CVE-2026-19906
was published
Aug 15, 2026
IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with...
Moderate
Unreviewed
CVE-2026-18531
was published
Aug 5, 2026
A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large...
Moderate
Unreviewed
CVE-2026-71225
was published
Aug 5, 2026
Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket....
Moderate
Unreviewed
CVE-2026-66391
was published
Jul 27, 2026
RabbitMQ has predictable credential obfuscation seed value used in Shovel and Federation plugins
Moderate
CVE-2022-31008
was published
for
rabbit_common
(Erlang)
Jun 30, 2026
Net::BitTorrent versions through 2.0.1 for Perl generate the MSE Diffie-Hellman private key with...
Moderate
Unreviewed
CVE-2026-57082
was published
Jun 30, 2026
Netty: QUIC stateless reset token material exposed through header-visible connection IDs
Moderate
CVE-2026-50009
was published
for
io.netty:netty-codec-classes-quic
(Maven)
Jun 15, 2026
Spring AMQP Has Predictable Correlation IDs in RabbitTemplate.sendAndReceive() with Fixed Reply Queue
Moderate
CVE-2026-41701
was published
for
org.springframework.amqp:spring-amqp
(Maven)
Jun 10, 2026
Spring Framework Predictable Session ID in WebSocket Module
Moderate
CVE-2026-41838
was published
for
org.springframework:spring-websocket
(Maven)
Jun 9, 2026
Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
Moderate
CVE-2026-45673
was published
for
io.netty:netty-resolver-dns
(Maven)
Jun 8, 2026
AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle
Moderate
CVE-2026-47703
was published
for
github.com/AdguardTeam/AdGuardHome
(Go)
Jun 4, 2026
netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failures
Moderate
CVE-2026-41207
was published
for
io.netty.incubator:netty-incubator-codec-ohttp
(Maven)
May 26, 2026
Netatalk 2.0.0 through 4.4.2 generates AFP session tokens derived from predictable process IDs,...
Moderate
Unreviewed
CVE-2026-44054
was published
May 21, 2026
Spring Boot's random value property source uses a weak PRNG unsuitable for secrets
Moderate
CVE-2026-40975
was published
for
org.springframework.boot:spring-boot-cassandra
(Maven)
Apr 28, 2026
DNN: Same HostGUID for all new installs
Moderate
CVE-2026-40306
was published
for
DotNetNuke.Core
(NuGet)
Apr 10, 2026
Duplicate Advisory: OpenClaw: Gemini OAuth exposed the PKCE verifier through the OAuth state parameter
Moderate
GHSA-ch86-pxr9-j9h9
was published
for
openclaw
(npm)
Apr 3, 2026
•
withdrawn
openssl-encrypt has non-cryptographic PRNG used for steganography pixel selection
Moderate
GHSA-vfgx-5q85-58q3
was published
for
openssl-encrypt
(pip)
Mar 31, 2026
Gradio has an Open Redirect in its OAuth Flow
Moderate
CVE-2026-28415
was published
for
gradio
(pip)
Mar 1, 2026
Fleet: Device lock PIN can be predicted if lock time is known
Moderate
CVE-2026-23999
was published
for
github.com/fleetdm/fleet/v4
(Go)
Feb 26, 2026
When connecting to the Solax Cloud MQTT server the username is the "registration number", which...
Moderate
Unreviewed
CVE-2025-15574
was published
Feb 12, 2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for...
Moderate
Unreviewed
CVE-2025-11723
was published
Jan 6, 2026
The Login Lockdown & Protection plugin for WordPress is vulnerable to IP Block Bypass in all...
Moderate
Unreviewed
CVE-2025-11707
was published
Dec 13, 2025
The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2025-12787
was published
Nov 11, 2025
ProTip!
Advisories are also available from the
GraphQL API