GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
783 advisories
Filter by severity
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could...
Low
Unreviewed
CVE-2026-73743
was published
Sep 1, 2026
pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
High
GHSA-vx52-2968-3vc6
was published
for
pnpm
(npm)
Sep 1, 2026
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
Moderate
CVE-2026-55860
was published
for
org.mariadb:r2dbc-mariadb
(Maven)
Aug 28, 2026
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
Moderate
CVE-2026-55857
was published
for
org.mariadb.jdbc:mariadb-java-client
(Maven)
Aug 28, 2026
MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
Moderate
CVE-2026-55854
was published
for
mariadb
(npm)
Aug 28, 2026
MQTT credentials and control traffic are transmitted in cleartext,
exposing sensitive...
Critical
Unreviewed
CVE-2026-69658
was published
Aug 28, 2026
A cleartext transmission of sensitive information vulnerability exists
in certain Ebyte gateway...
High
Unreviewed
CVE-2026-73809
was published
Aug 28, 2026
openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and...
High
Unreviewed
CVE-2026-81691
was published
Aug 27, 2026
When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks...
Moderate
Unreviewed
CVE-2026-19854
was published
Aug 27, 2026
A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple...
High
Unreviewed
CVE-2026-29988
was published
Aug 26, 2026
rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing...
Moderate
Unreviewed
CVE-2026-79779
was published
Aug 25, 2026
rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes...
Critical
Unreviewed
CVE-2026-79782
was published
Aug 25, 2026
When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in...
Moderate
Unreviewed
CVE-2026-77131
was published
Aug 25, 2026
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions...
High
Unreviewed
CVE-2026-12556
was published
Aug 24, 2026
A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During...
Moderate
Unreviewed
CVE-2026-19683
was published
Aug 20, 2026
Download of code without integrity check, inclusion of functionality from untrusted control...
Critical
Unreviewed
CVE-2026-22306
was published
Aug 19, 2026
stigmem-node contains an insecure default configuration vulnerability that allows federation...
Critical
Unreviewed
CVE-2026-76244
was published
Aug 19, 2026
The HTTPPasswordMgr class in the urllib.request module, along with its subclasses...
Moderate
Unreviewed
CVE-2026-15806
was published
Aug 18, 2026
atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)
High
GHSA-xhcr-cqfr-m3hv
was published
for
atomic-agents-stack
(pip)
Aug 17, 2026
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
Low
GHSA-gx4c-2hqx-cw2r
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
Moderate
GHSA-h4mf-4v27-hggj
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
Moderate
GHSA-8mxv-9xhp-86h4
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could...
Moderate
Unreviewed
CVE-2026-20294
was published
Aug 5, 2026
This issue was addressed by using HTTPS when sending information over the network. This issue is...
Moderate
Unreviewed
CVE-2026-64742
was published
Jul 27, 2026
Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext...
Moderate
Unreviewed
CVE-2026-3182
was published
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API