GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
12,902 advisories
Filter by severity
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
High
GHSA-xmf8-cvqr-rfgj
was published
for
@auth/core
(npm)
Jul 23, 2026
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This...
Critical
Unreviewed
CVE-2026-16723
was published
Jul 23, 2026
A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function...
Moderate
Unreviewed
CVE-2026-16632
was published
Jul 23, 2026
n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
Moderate
GHSA-9cmh-xcqm-5hqr
was published
for
n8n
(npm)
Jul 22, 2026
Eclipse Jetty: HTTP Authority/Host mismatch
Moderate
CVE-2026-6790
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Jul 22, 2026
An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user...
Moderate
Unreviewed
CVE-2026-13057
was published
Jul 22, 2026
Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
Moderate
CVE-2026-56722
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
Dompdf: Chroot Validation Bypass
Low
CVE-2026-55554
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input...
High
Unreviewed
CVE-2026-40714
was published
Jul 22, 2026
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input...
Critical
Unreviewed
CVE-2026-46738
was published
Jul 22, 2026
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input...
Moderate
Unreviewed
CVE-2026-46737
was published
Jul 22, 2026
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input...
Critical
Unreviewed
CVE-2026-40712
was published
Jul 22, 2026
In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set,...
High
Unreviewed
CVE-2026-55973
was published
Jul 22, 2026
Insufficient validation of input parameters in the firmware of some Hikvision cameras allows...
High
Unreviewed
CVE-2026-57600
was published
Jul 22, 2026
Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a...
High
Unreviewed
CVE-2026-16421
was published
Jul 22, 2026
Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150...
High
Unreviewed
CVE-2026-16422
was published
Jul 22, 2026
Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182...
High
Unreviewed
CVE-2026-16414
was published
Jul 22, 2026
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182...
Moderate
Unreviewed
CVE-2026-16415
was published
Jul 22, 2026
Vulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component:...
Moderate
Unreviewed
CVE-2026-62519
was published
Jul 22, 2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product...
High
Unreviewed
CVE-2026-61160
was published
Jul 22, 2026
Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected...
Moderate
Unreviewed
CVE-2026-61079
was published
Jul 22, 2026
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API)...
Critical
Unreviewed
CVE-2026-60719
was published
Jul 22, 2026
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component:...
High
Unreviewed
CVE-2026-60638
was published
Jul 22, 2026
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component:...
High
Unreviewed
CVE-2026-60636
was published
Jul 22, 2026
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component:...
High
Unreviewed
CVE-2026-60639
was published
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API