GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
11,423 advisories
Filter by severity
rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail...
Moderate
Unreviewed
CVE-2026-79776
was published
Aug 25, 2026
rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3...
Moderate
Unreviewed
CVE-2026-79780
was published
Aug 25, 2026
phpMyFAQ public FAQ APIs expose inactive FAQ content
Moderate
GHSA-mf8r-wm2w-f8c5
was published
for
phpmyfaq/phpmyfaq
(Composer)
Aug 25, 2026
urllib's cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage
High
CVE-2026-55553
was published
for
urllib
(npm)
Aug 25, 2026
Ech0 versions before 4.7.3 expose guest commenter email addresses through public API endpoints...
Moderate
Unreviewed
CVE-2026-79660
was published
Aug 25, 2026
HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker...
Low
Unreviewed
CVE-2026-21758
was published
Aug 25, 2026
Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed...
High
Unreviewed
CVE-2026-72698
was published
Aug 25, 2026
RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys...
Critical
Unreviewed
CVE-2026-78555
was published
Aug 24, 2026
Unauthenticated REST disclosure of certain content items in Apache Allura.
This issue affects...
Moderate
Unreviewed
CVE-2026-75099
was published
Aug 24, 2026
Ransomlook contains a Redis glob pattern injection vulnerability caused by insufficient...
Moderate
Unreviewed
CVE-2026-78378
was published
Aug 24, 2026
RansomLook exposed sensitive operator-side scraping configuration through multiple...
High
Unreviewed
CVE-2026-78386
was published
Aug 24, 2026
WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken...
High
Unreviewed
CVE-2026-59256
was published
Aug 22, 2026
AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php...
Moderate
Unreviewed
CVE-2026-56380
was published
Aug 22, 2026
The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected...
Moderate
Unreviewed
CVE-2026-16612
was published
Aug 22, 2026
There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and...
Moderate
Unreviewed
CVE-2026-69224
was published
Aug 21, 2026
There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through...
Moderate
Unreviewed
CVE-2026-69225
was published
Aug 21, 2026
Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability...
High
Unreviewed
CVE-2026-50222
was published
Aug 21, 2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's...
High
Unreviewed
CVE-2026-59655
was published
Aug 21, 2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's...
High
Unreviewed
CVE-2026-59780
was published
Aug 21, 2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's...
High
Unreviewed
CVE-2026-61397
was published
Aug 21, 2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's...
Moderate
Unreviewed
CVE-2026-65613
was published
Aug 21, 2026
The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before...
Low
Unreviewed
CVE-2026-19435
was published
Aug 21, 2026
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0...
Moderate
Unreviewed
CVE-2026-16575
was published
Aug 21, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages...
Moderate
Unreviewed
CVE-2026-16964
was published
Aug 21, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to disclose sensitive...
Moderate
Unreviewed
CVE-2026-16973
was published
Aug 21, 2026
ProTip!
Advisories are also available from the
GraphQL API