GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,430 advisories
Filter by severity
An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks...
Low
Unreviewed
CVE-2026-0290
was published
Aug 13, 2026
SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system...
Critical
Unreviewed
CVE-2026-72793
was published
Aug 12, 2026
siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system...
Critical
Unreviewed
CVE-2026-72794
was published
Aug 12, 2026
SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped...
High
Unreviewed
CVE-2026-72801
was published
Aug 12, 2026
Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker...
Moderate
Unreviewed
CVE-2026-62882
was published
Aug 11, 2026
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker...
Moderate
Unreviewed
CVE-2026-62839
was published
Aug 11, 2026
A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system...
Moderate
Unreviewed
CVE-2026-71577
was published
Aug 10, 2026
Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve...
High
Unreviewed
CVE-2026-12984
was published
Aug 10, 2026
The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently...
Moderate
Unreviewed
CVE-2026-21766
was published
Aug 5, 2026
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
Low
GHSA-gx4c-2hqx-cw2r
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
Moderate
GHSA-h4mf-4v27-hggj
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
Moderate
GHSA-8mxv-9xhp-86h4
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
Statamic CMS exposes two-factor recovery codes through dynamic Antlers rendering
Moderate
CVE-2026-71293
was published
for
statamic/cms
(Composer)
Aug 5, 2026
ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In...
Moderate
Unreviewed
CVE-2026-71260
was published
Aug 5, 2026
HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive...
Low
Unreviewed
CVE-2026-56570
was published
Jul 31, 2026
/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0,...
Critical
Unreviewed
CVE-2026-17349
was published
Jul 31, 2026
Wings exposes node configuration secrets through egg configuration-file templating
Critical
CVE-2026-52855
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will...
High
Unreviewed
CVE-2026-15977
was published
Jul 30, 2026
A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext...
Moderate
Unreviewed
CVE-2026-15657
was published
Jul 30, 2026
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
Critical
CVE-2026-67426
was published
for
flyto-core
(pip)
Jul 30, 2026
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
High
CVE-2026-67425
was published
for
flyto-core
(pip)
Jul 30, 2026
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
High
CVE-2026-67427
was published
for
flyto-core
(pip)
Jul 30, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1...
Moderate
Unreviewed
CVE-2026-16553
was published
Jul 29, 2026
CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication...
High
Unreviewed
CVE-2026-14354
was published
Jul 29, 2026
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
High
CVE-2026-54660
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
ProTip!
Advisories are also available from the
GraphQL API