GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
6,587 advisories
Filter by severity
A vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low...
Moderate
Unreviewed
CVE-2026-73741
was published
Sep 1, 2026
When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly...
High
Unreviewed
CVE-2026-18664
was published
Sep 1, 2026
A vulnerability exists in the affected products that allows a threat actor to create a project...
High
Unreviewed
CVE-2024-7953
was published
Sep 1, 2026
Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows...
High
Unreviewed
CVE-2026-51766
was published
Sep 1, 2026
Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows...
Moderate
Unreviewed
CVE-2026-51761
was published
Sep 1, 2026
Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015...
Moderate
Unreviewed
CVE-2026-51752
was published
Sep 1, 2026
Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu...
Moderate
Unreviewed
CVE-2026-51748
was published
Sep 1, 2026
Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015...
Moderate
Unreviewed
CVE-2026-51756
was published
Sep 1, 2026
Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155.
High
Unreviewed
CVE-2026-84128
was published
Sep 1, 2026
Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015...
Critical
Unreviewed
CVE-2026-51743
was published
Sep 1, 2026
Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows...
Moderate
Unreviewed
CVE-2026-51742
was published
Sep 1, 2026
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.
High
Unreviewed
CVE-2026-84117
was published
Sep 1, 2026
Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015...
Moderate
Unreviewed
CVE-2026-51745
was published
Sep 1, 2026
Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy...
Critical
Unreviewed
CVE-2026-84200
was published
Sep 1, 2026
AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows...
High
Unreviewed
CVE-2026-84187
was published
Sep 1, 2026
A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems,...
High
Unreviewed
CVE-2026-84165
was published
Sep 1, 2026
A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function...
Moderate
Unreviewed
CVE-2026-82921
was published
Sep 1, 2026
Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015...
Critical
Unreviewed
CVE-2026-51734
was published
Aug 31, 2026
Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu...
Moderate
Unreviewed
CVE-2026-51739
was published
Aug 31, 2026
Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows...
High
Unreviewed
CVE-2026-51735
was published
Aug 31, 2026
Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows...
Critical
Unreviewed
CVE-2026-51740
was published
Aug 31, 2026
Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015...
Moderate
Unreviewed
CVE-2026-51737
was published
Aug 31, 2026
Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows...
Critical
Unreviewed
CVE-2026-51736
was published
Aug 31, 2026
Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015...
Moderate
Unreviewed
CVE-2026-51732
was published
Aug 31, 2026
Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows...
Critical
Unreviewed
CVE-2026-51731
was published
Aug 31, 2026
ProTip!
Advisories are also available from the
GraphQL API