GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
11,423 advisories
Filter by severity
Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who...
Unknown
Unreviewed
CVE-2026-84359
was published
Sep 2, 2026
Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote...
Unknown
Unreviewed
CVE-2026-84348
was published
Sep 2, 2026
WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager...
Moderate
Unreviewed
CVE-2026-84481
was published
Sep 2, 2026
A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow...
Moderate
Unreviewed
CVE-2026-73732
was published
Sep 1, 2026
A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow...
Moderate
Unreviewed
CVE-2026-73738
was published
Sep 1, 2026
A vulnerability exists in the API of HPE Networking Fabric Composer that allows for an attacker...
Moderate
Unreviewed
CVE-2026-73739
was published
Sep 1, 2026
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
Moderate
CVE-2026-73229
was published
for
djangorestframework
(pip)
Sep 1, 2026
Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability...
Moderate
Unreviewed
CVE-2026-84127
was published
Sep 1, 2026
An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest...
Moderate
Unreviewed
CVE-2026-53682
was published
Sep 1, 2026
Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to...
High
Unreviewed
CVE-2026-84195
was published
Sep 1, 2026
The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its...
Moderate
Unreviewed
CVE-2026-13611
was published
Sep 1, 2026
Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController...
High
Unreviewed
CVE-2026-80194
was published
Aug 31, 2026
A security flaw has been discovered in vidIQ Vision for YouTube Extension 3.199.0 on Chrome. The...
Low
Unreviewed
CVE-2026-82809
was published
Aug 31, 2026
A weakness has been identified in extension.vn 2FA Authenticator Extension 1.0.0.2 on Chrome. The...
Low
Unreviewed
CVE-2026-82810
was published
Aug 31, 2026
A flaw has been found in code-projects Simple Inventory System 1.0. Affected by this issue is...
Moderate
Unreviewed
CVE-2026-82624
was published
Aug 31, 2026
Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for...
High
Unreviewed
CVE-2026-82657
was published
Aug 30, 2026
SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg...
Moderate
Unreviewed
CVE-2026-82651
was published
Aug 30, 2026
A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an...
Moderate
Unreviewed
CVE-2026-82548
was published
Aug 30, 2026
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not...
High
Unreviewed
CVE-2026-77007
was published
Aug 29, 2026
StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail...
Moderate
Unreviewed
CVE-2026-82306
was published
Aug 28, 2026
Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref
Moderate
CVE-2026-55406
was published
for
buffa
(Rust)
Aug 28, 2026
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
High
CVE-2026-55485
was published
for
piccolo-admin
(pip)
Aug 28, 2026
WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and...
Moderate
Unreviewed
CVE-2026-81732
was published
Aug 28, 2026
The comparison used for the doveadm password and API key is not fully timing safe and can reveal...
Low
Unreviewed
CVE-2026-42393
was published
Aug 28, 2026
An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes...
Moderate
Unreviewed
CVE-2026-42392
was published
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API