GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,683
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,532
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
324 advisories
Filter by severity
Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback
High
CVE-2026-50285
was published
for
github.com/pomerium/pomerium
(Go)
Jul 15, 2026
Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment –...
Moderate
Unreviewed
CVE-2026-57364
was published
Jul 13, 2026
An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding...
High
Unreviewed
CVE-2026-57019
was published
Jul 10, 2026
An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of...
High
Unreviewed
CVE-2026-57023
was published
Jul 10, 2026
pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too small
Moderate
CVE-2026-53720
was published
for
pymonocypher
(pip)
Jul 9, 2026
internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments,...
Moderate
Unreviewed
CVE-2026-59997
was published
Jul 8, 2026
** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI...
High
Unreviewed
CVE-2022-4990
was published
Jul 3, 2026
** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI...
High
Unreviewed
CVE-2022-4989
was published
Jul 3, 2026
Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.
Critical
Unreviewed
CVE-2026-57623
was published
Jul 2, 2026
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes...
Moderate
Unreviewed
CVE-2026-11906
was published
Jun 30, 2026
Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions.
High
Unreviewed
CVE-2026-56035
was published
Jun 26, 2026
golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS
High
CVE-2026-39829
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
Improper input validation in the PAM AD discovery endpoints in
Devolutions Server 2026.2.4.0...
Low
Unreviewed
CVE-2026-12755
was published
Jun 25, 2026
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode...
Moderate
Unreviewed
CVE-2026-57053
was published
Jun 23, 2026
CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS...
Low
Unreviewed
CVE-2026-57062
was published
Jun 23, 2026
Craft Commerce: Partial Payment Amount Without Lower Bound Validation
Moderate
GHSA-78vr-q6cf-c7p6
was published
for
craftcms/commerce
(Composer)
Jun 19, 2026
NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to...
Moderate
Unreviewed
CVE-2026-55392
was published
Jun 18, 2026
spomky-labs/otphp: Unbounded digits parameter in a provisioning URI triggers an uncaught DivisionByZeroError in OTP generation
High
GHSA-g7m4-839x-ch6v
was published
for
spomky-labs/otphp
(Composer)
Jun 18, 2026
sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass...
Moderate
Unreviewed
CVE-2026-55706
was published
Jun 17, 2026
Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.
High
Unreviewed
CVE-2026-49110
was published
Jun 15, 2026
Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.
High
Unreviewed
CVE-2026-49078
was published
Jun 15, 2026
Unauthenticated Other Vulnerability Type in WpEvently <= 5.3.3 versions.
High
Unreviewed
CVE-2026-45441
was published
Jun 15, 2026
Unauthenticated Other Vulnerability Type in Contest Gallery <= 28.1.7 versions.
Moderate
Unreviewed
CVE-2026-42657
was published
Jun 15, 2026
python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
Low
CVE-2026-53540
was published
for
python-multipart
(pip)
Jun 15, 2026
File Browser has a DoS Vulnerability via Public Login API
High
CVE-2026-54092
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
ProTip!
Advisories are also available from the
GraphQL API