GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
128 advisories
Filter by severity
golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS
High
CVE-2026-39829
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
spomky-labs/otphp: Unbounded digits parameter in a provisioning URI triggers an uncaught DivisionByZeroError in OTP generation
High
GHSA-g7m4-839x-ch6v
was published
for
spomky-labs/otphp
(Composer)
Jun 18, 2026
Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.
High
Unreviewed
CVE-2026-49078
was published
Jun 15, 2026
Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.
High
Unreviewed
CVE-2026-49110
was published
Jun 15, 2026
Unauthenticated Other Vulnerability Type in WpEvently <= 5.3.3 versions.
High
Unreviewed
CVE-2026-45441
was published
Jun 15, 2026
File Browser has a DoS Vulnerability via Public Login API
High
CVE-2026-54092
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability,...
High
Unreviewed
CVE-2026-12059
was published
Jun 12, 2026
libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer...
High
Unreviewed
CVE-2026-53689
was published
Jun 10, 2026
ExifReader is vulnerable to denial of service via crafted ICC `mluc` tag
High
CVE-2026-8813
was published
for
exifreader
(npm)
May 29, 2026
In the Linux kernel, the following vulnerability has been resolved:
crypto: authencesn - reject...
High
Unreviewed
CVE-2026-46033
was published
May 27, 2026
A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name ...
High
Unreviewed
CVE-2026-42013
was published
May 27, 2026
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret...
High
Unreviewed
CVE-2026-5260
was published
May 27, 2026
The affected products perform improper length checking when parsing incoming HTTP requests,...
High
Unreviewed
CVE-2026-8047
was published
May 26, 2026
iskorotkov/avro: CPU Exhaustion in Decoder
High
CVE-2026-46385
was published
for
github.com/iskorotkov/avro/v2
(Go)
May 18, 2026
iskorotkov/avro: Integer Overflow in Decoder
High
CVE-2026-46384
was published
for
github.com/iskorotkov/avro/v2
(Go)
May 18, 2026
iskorotkov/avro: Denial-of-Service Vulnerability in Decoder
High
GHSA-mx64-mj3q-7prj
was published
for
github.com/iskorotkov/avro/v2
(Go)
May 18, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18...
High
Unreviewed
CVE-2025-14869
was published
May 14, 2026
Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()`
High
CVE-2026-44635
was published
for
kysely
(npm)
May 11, 2026
Conditional Fields for Contact Form 7 WordPress plugin through version 2.6.7 contains an...
High
Unreviewed
CVE-2026-25863
was published
May 4, 2026
An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the...
High
Unreviewed
CVE-2025-70069
was published
May 4, 2026
A vulnerability exists in the command handling of the IEC 61850 communication stack included in...
High
Unreviewed
CVE-2025-3756
was published
Apr 13, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.8.9,...
High
Unreviewed
CVE-2026-1092
was published
Apr 9, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18...
High
Unreviewed
CVE-2025-12664
was published
Apr 9, 2026
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0....
High
Unreviewed
CVE-2026-30573
was published
Apr 1, 2026
GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2026-3085
was published
Mar 16, 2026
ProTip!
Advisories are also available from the
GraphQL API