GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
13,124 advisories
Filter by severity
Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote...
Unknown
Unreviewed
CVE-2026-84357
was published
Sep 2, 2026
Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a...
Unknown
Unreviewed
CVE-2026-84325
was published
Sep 2, 2026
Socket.IO: Engine.IO WebTransport SID DoS
High
CVE-2026-59724
was published
for
engine.io
(npm)
Aug 31, 2026
Improper input validation vulnerability in Extend Themes Kubio AI Website Builder.
This issue...
Moderate
Unreviewed
CVE-2026-83492
was published
Aug 31, 2026
A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown...
Moderate
Unreviewed
CVE-2026-82550
was published
Aug 30, 2026
WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the...
High
Unreviewed
CVE-2026-82648
was published
Aug 30, 2026
NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in...
High
Unreviewed
CVE-2026-82639
was published
Aug 30, 2026
A malicious actor with access to the network could exploit an Improper Input Validation...
Critical
Unreviewed
CVE-2026-77554
was published
Aug 28, 2026
A malicious actor with access to the network and low privileges could exploit an Improper Input...
Critical
Unreviewed
CVE-2026-77546
was published
Aug 28, 2026
A malicious actor with access to the network and high privileges could exploit an Improper Input...
Critical
Unreviewed
CVE-2026-77535
was published
Aug 28, 2026
A malicious actor with access to the network and low privileges could exploit an Improper Input...
Critical
Unreviewed
CVE-2026-77543
was published
Aug 28, 2026
A malicious actor with access to the network and low privileges could exploit an Improper Input...
Critical
Unreviewed
CVE-2026-77547
was published
Aug 28, 2026
A malicious actor with access to the network and high privileges could exploit an Improper Input...
Critical
Unreviewed
CVE-2026-77542
was published
Aug 28, 2026
A malicious actor with access to the network and low privileges could exploit an Improper Input...
Critical
Unreviewed
CVE-2026-77548
was published
Aug 28, 2026
A malicious actor with access to the network could exploit an Improper Input Validation...
Critical
Unreviewed
CVE-2026-77537
was published
Aug 28, 2026
A malicious actor with access to the network could exploit an Improper Input Validation...
Critical
Unreviewed
CVE-2026-77552
was published
Aug 28, 2026
Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation
High
CVE-2026-55212
was published
for
pimcore/studio-backend-bundle
(Composer)
Aug 28, 2026
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints
Critical
CVE-2026-55068
was published
for
github.com/free5gc/free5gc
(Go)
Aug 28, 2026
An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote...
High
Unreviewed
CVE-2026-78009
was published
Aug 28, 2026
The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in...
Moderate
Unreviewed
CVE-2026-59322
was published
Aug 27, 2026
Potential for improper filtering of HTTP headers in Spring Cloud Function.
Spring Cloud Function...
Low
Unreviewed
CVE-2026-59298
was published
Aug 27, 2026
A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare...
Critical
Unreviewed
CVE-2026-35869
was published
Aug 27, 2026
A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare...
Critical
Unreviewed
CVE-2026-35868
was published
Aug 27, 2026
Affected versions of Flowintel incorrectly attempted to validate login email addresses by calling...
Moderate
Unreviewed
CVE-2026-81827
was published
Aug 27, 2026
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents,...
Critical
Unreviewed
CVE-2026-81707
was published
Aug 27, 2026
ProTip!
Advisories are also available from the
GraphQL API