GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,578
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
96 advisories
Filter by severity
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password...
Moderate
Unreviewed
CVE-2026-75010
was published
Aug 17, 2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI...
Moderate
Unreviewed
CVE-2026-75003
was published
Aug 17, 2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the...
Moderate
Unreviewed
CVE-2026-75000
was published
Aug 17, 2026
In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the...
Low
Unreviewed
CVE-2026-73574
was published
Aug 13, 2026
In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving...
Moderate
Unreviewed
CVE-2026-71194
was published
Aug 13, 2026
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to...
Low
Unreviewed
CVE-2026-73281
was published
Aug 11, 2026
Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote...
Critical
Unreviewed
CVE-2026-14151
was published
Jul 1, 2026
OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints
Moderate
CVE-2026-46448
was published
for
nova
(pip)
Jun 16, 2026
Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may...
High
Unreviewed
CVE-2026-12068
was published
Jun 13, 2026
OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read...
Moderate
Unreviewed
CVE-2026-44917
was published
Jun 4, 2026
OpenStack Ironic allows Boot Script Injection
Moderate
CVE-2026-46447
was published
for
ironic
(pip)
Jun 4, 2026
Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary...
Low
Unreviewed
CVE-2026-48847
was published
May 26, 2026
In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image...
Moderate
Unreviewed
CVE-2026-48845
was published
May 26, 2026
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking...
Moderate
Unreviewed
CVE-2026-48846
was published
May 26, 2026
Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several...
High
Unreviewed
CVE-2026-48831
was published
May 26, 2026
Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.
Low
Unreviewed
CVE-2026-44599
was published
May 7, 2026
Talos Linux has a local privilege escalation from untrusted workloads
High
GHSA-m38g-vww2-mvgx
was published
for
github.com/siderolabs/talos
(Go)
May 7, 2026
OpenStack Ironic has an Incorrect Resource Transfer Between Spheres
High
CVE-2026-42997
was published
for
ironic-python-agent
(pip)
May 5, 2026
mpGabinet is vulnerable to Remote Command Execution. An authorized user with access to the...
Moderate
Unreviewed
CVE-2026-40552
was published
Apr 28, 2026
KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to...
Moderate
Unreviewed
CVE-2026-41525
was published
Apr 28, 2026
In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert...
High
Unreviewed
CVE-2026-31431
was published
Apr 22, 2026
In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions...
Moderate
Unreviewed
CVE-2026-41030
was published
Apr 16, 2026
In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary...
Low
Unreviewed
CVE-2026-40228
was published
Apr 10, 2026
In udev in systemd before 260, local root execution can occur via malicious hardware devices and...
Moderate
Unreviewed
CVE-2026-40225
was published
Apr 10, 2026
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
Moderate
CVE-2026-35544
was published
for
roundcube/roundcubemail
(Composer)
Apr 3, 2026
ProTip!
Advisories are also available from the
GraphQL API