GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,683
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,532
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
324 advisories
Filter by severity
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
High
CVE-2026-82397
was published
for
tornado
(pip)
Sep 2, 2026
Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X...
Critical
Unreviewed
CVE-2026-81779
was published
Aug 31, 2026
DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an...
Moderate
Unreviewed
CVE-2026-59317
was published
Aug 27, 2026
Software installed and run as a non-privileged user may conduct improper GPU system calls to pass...
High
Unreviewed
CVE-2026-45201
was published
Aug 21, 2026
tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream...
Low
Unreviewed
CVE-2026-77640
was published
Aug 20, 2026
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). ...
High
Unreviewed
CVE-2026-60820
was published
Aug 18, 2026
Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size...
High
Unreviewed
CVE-2026-75897
was published
Aug 18, 2026
Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions.
Moderate
Unreviewed
CVE-2026-66679
was published
Aug 18, 2026
An improper access control vulnerability exists where an authenticated non-administrative...
Moderate
Unreviewed
CVE-2026-19639
was published
Aug 14, 2026
Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie...
Moderate
Unreviewed
CVE-2026-19518
was published
Aug 11, 2026
GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory()...
Moderate
Unreviewed
CVE-2026-71394
was published
Aug 10, 2026
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
High
CVE-2026-71314
was published
for
nuxt
(npm)
Aug 5, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco...
High
Unreviewed
CVE-2026-20313
was published
Aug 5, 2026
imagecli's `carve <ratio>` pipeline operation (Carve::apply() in src/image_ops.rs) only asserts ...
High
Unreviewed
CVE-2026-70378
was published
Aug 5, 2026
Improper Input Validation in the decode() function of the traceparser library could allow an...
High
Unreviewed
CVE-2026-40272
was published
Jul 29, 2026
Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
High
Unreviewed
CVE-2026-59532
was published
Jul 27, 2026
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
High
Unreviewed
CVE-2026-59531
was published
Jul 27, 2026
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the...
High
Unreviewed
CVE-2026-66374
was published
Jul 25, 2026
It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller...
High
Unreviewed
CVE-2026-11721
was published
Jul 22, 2026
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is...
High
Unreviewed
CVE-2026-32665
was published
Jul 22, 2026
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
High
CVE-2026-59879
was published
for
immutable
(npm)
Jul 21, 2026
Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
Moderate
CVE-2026-59930
was published
for
mistune
(pip)
Jul 20, 2026
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated...
High
Unreviewed
CVE-2026-59695
was published
Jul 17, 2026
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated...
High
Unreviewed
CVE-2026-59694
was published
Jul 17, 2026
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated...
High
Unreviewed
CVE-2026-59252
was published
Jul 17, 2026
ProTip!
Advisories are also available from the
GraphQL API