GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,430 advisories
Filter by severity
Statamic CMS exposes two-factor recovery codes through dynamic Antlers rendering
Moderate
CVE-2026-71293
was published
for
statamic/cms
(Composer)
Aug 5, 2026
pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
High
GHSA-vx52-2968-3vc6
was published
for
pnpm
(npm)
Sep 1, 2026
MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials
High
GHSA-3f6p-5ww8-9rcr
was published
for
mysql2
(npm)
Sep 1, 2026
A flaw was found in the authentication configuration endpoint of the keycloak-services component,...
Moderate
Unreviewed
CVE-2026-16104
was published
Jul 17, 2026
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
Moderate
CVE-2026-55860
was published
for
org.mariadb:r2dbc-mariadb
(Maven)
Aug 28, 2026
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
Moderate
CVE-2026-55857
was published
for
org.mariadb.jdbc:mariadb-java-client
(Maven)
Aug 28, 2026
MariaDB has cleartext password disclosure to a MITM on the initial-handshake
Moderate
CVE-2026-55856
was published
for
org.mariadb.jdbc:mariadb-java-client
(Maven)
Aug 28, 2026
MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
Moderate
CVE-2026-55854
was published
for
mariadb
(npm)
Aug 28, 2026
Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the ...
High
Unreviewed
CVE-2026-82288
was published
Aug 28, 2026
MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`
High
CVE-2026-55215
was published
for
mariadb
(npm)
Aug 28, 2026
gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based...
High
Unreviewed
CVE-2026-82255
was published
Aug 28, 2026
gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not...
High
Unreviewed
CVE-2026-82247
was published
Aug 28, 2026
Administrative credentials may be exposed in plaintext within the Ebyte
device's management...
Moderate
Unreviewed
CVE-2026-73839
was published
Aug 28, 2026
A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter...
High
Unreviewed
CVE-2026-64632
was published
Aug 27, 2026
Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected...
High
Unreviewed
CVE-2026-75960
was published
Aug 26, 2026
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
Critical
GHSA-93qj-5q5v-3c2h
was published
for
pantheon-agents
(pip)
Aug 26, 2026
NVIDIA NemoClaw contains a vulnerability where an attacker could cause
insufficiently protected...
Moderate
Unreviewed
CVE-2026-65087
was published
Aug 25, 2026
urllib's cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage
High
CVE-2026-55553
was published
for
urllib
(npm)
Aug 25, 2026
Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow...
High
Unreviewed
CVE-2026-76839
was published
Aug 25, 2026
Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that...
High
Unreviewed
CVE-2026-76846
was published
Aug 25, 2026
Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API...
High
Unreviewed
CVE-2026-71511
was published
Aug 24, 2026
Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client...
Moderate
Unreviewed
CVE-2025-15621
was published
Apr 16, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco...
Critical
Unreviewed
CVE-2026-20359
was published
Aug 19, 2026
Azure Active Directory Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2021-42306
was published
Nov 25, 2021
A rogue webpage could override the injected WKUserScript used by the logins autofill, this...
Moderate
Unreviewed
CVE-2020-15661
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API