GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
12,902 advisories
Filter by severity
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure
Critical
CVE-2026-53713
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly...
Critical
Unreviewed
CVE-2026-11386
was published
Jul 16, 2026
serde_with: KeyValueMap serialization panics on empty sequence or map entries
Moderate
GHSA-7gcf-g7xr-8hxj
was published
for
serde_with
(Rust)
Jul 15, 2026
Pixeldrain API key shared with unverified thirdparty sites
Moderate
CVE-2026-54254
was published
for
cyberdrop-dl-patched
(pip)
Jul 15, 2026
CVE-2026-40958
is a input validation error in Secure Access clients prior to 14.55. Attackers...
Low
Unreviewed
CVE-2026-40958
was published
Jul 15, 2026
MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs
Moderate
CVE-2026-52883
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
Pegatron `Tdelo64.sys` exposes a privileged device interface, `\\.\TdeIo`, that fails to properly...
Moderate
Unreviewed
CVE-2026-14961
was published
Jul 15, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS...
High
Unreviewed
CVE-2026-20153
was published
Jul 15, 2026
PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default:...
Moderate
Unreviewed
CVE-2026-61427
was published
Jul 15, 2026
n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that...
Moderate
Unreviewed
CVE-2026-56349
was published
Jul 15, 2026
Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth...
High
Unreviewed
CVE-2026-56398
was published
Jul 15, 2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead...
Moderate
Unreviewed
CVE-2026-48353
was published
Jul 15, 2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could...
High
Unreviewed
CVE-2026-48351
was published
Jul 15, 2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could...
High
Unreviewed
CVE-2026-48352
was published
Jul 15, 2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could...
Moderate
Unreviewed
CVE-2026-48302
was published
Jul 15, 2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could...
Moderate
Unreviewed
CVE-2026-48312
was published
Jul 15, 2026
Illustrator is affected by an Improper Input Validation vulnerability that could result in...
Critical
Unreviewed
CVE-2026-48334
was published
Jul 15, 2026
Premiere Pro is affected by an Improper Input Validation vulnerability that could result in a...
Moderate
Unreviewed
CVE-2026-48308
was published
Jul 14, 2026
ColdFusion is affected by an Improper Input Validation vulnerability that could result in a...
High
Unreviewed
CVE-2026-48328
was published
Jul 14, 2026
ColdFusion is affected by an Improper Input Validation vulnerability that could result in...
Critical
Unreviewed
CVE-2026-48284
was published
Jul 14, 2026
Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux...
High
Unreviewed
CVE-2026-15769
was published
Jul 14, 2026
NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API...
Moderate
Unreviewed
CVE-2026-47470
was published
Jul 14, 2026
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125...
Moderate
Unreviewed
CVE-2026-15778
was published
Jul 14, 2026
Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0...
Moderate
Unreviewed
CVE-2026-15771
was published
Jul 14, 2026
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to...
Critical
Unreviewed
CVE-2026-13001
was published
Jul 14, 2026
ProTip!
Advisories are also available from the
GraphQL API