GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,683
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,532
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
152 advisories
Filter by severity
DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an...
Moderate
Unreviewed
CVE-2026-59317
was published
Aug 27, 2026
Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions.
Moderate
Unreviewed
CVE-2026-66679
was published
Aug 18, 2026
An improper access control vulnerability exists where an authenticated non-administrative...
Moderate
Unreviewed
CVE-2026-19639
was published
Aug 14, 2026
Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie...
Moderate
Unreviewed
CVE-2026-19518
was published
Aug 11, 2026
GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory()...
Moderate
Unreviewed
CVE-2026-71394
was published
Aug 10, 2026
Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
Moderate
CVE-2026-59930
was published
for
mistune
(pip)
Jul 20, 2026
Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment –...
Moderate
Unreviewed
CVE-2026-57364
was published
Jul 13, 2026
pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too small
Moderate
CVE-2026-53720
was published
for
pymonocypher
(pip)
Jul 9, 2026
internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments,...
Moderate
Unreviewed
CVE-2026-59997
was published
Jul 8, 2026
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes...
Moderate
Unreviewed
CVE-2026-11906
was published
Jun 30, 2026
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode...
Moderate
Unreviewed
CVE-2026-57053
was published
Jun 23, 2026
Craft Commerce: Partial Payment Amount Without Lower Bound Validation
Moderate
GHSA-78vr-q6cf-c7p6
was published
for
craftcms/commerce
(Composer)
Jun 19, 2026
NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to...
Moderate
Unreviewed
CVE-2026-55392
was published
Jun 18, 2026
sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass...
Moderate
Unreviewed
CVE-2026-55706
was published
Jun 17, 2026
Unauthenticated Other Vulnerability Type in Contest Gallery <= 28.1.7 versions.
Moderate
Unreviewed
CVE-2026-42657
was published
Jun 15, 2026
In ScreenConnect™ versions prior to 26.2, input
validation within the Host Pass creation...
Moderate
Unreviewed
CVE-2026-11596
was published
Jun 10, 2026
In the Linux kernel, the following vulnerability has been resolved:
mm/damon/core: disallow non...
Moderate
Unreviewed
CVE-2026-52905
was published
Jun 9, 2026
Keycloak Vulnerable to Improper Validation of Specified Quantity in Input
Moderate
CVE-2026-9801
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
May 28, 2026
IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by...
Moderate
Unreviewed
CVE-2026-7254
was published
May 27, 2026
Keycloak Vulnerable to Improper Validation of Specified Quantity in Input
Moderate
CVE-2026-9704
was published
for
org.keycloak:keycloak-server-spi-private
(Maven)
May 27, 2026
IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux,...
Moderate
Unreviewed
CVE-2026-3676
was published
May 27, 2026
Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads...
Moderate
Unreviewed
CVE-2026-42744
was published
May 27, 2026
Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads...
Moderate
Unreviewed
CVE-2026-42732
was published
May 27, 2026
Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU...
Moderate
Unreviewed
CVE-2025-15645
was published
May 20, 2026
oxidize-pdf: NaN/inf bypass in colour content-stream emission causes PDF rejection (DoS)
Moderate
GHSA-88q9-cmp2-c2vq
was published
for
OxidizePdf.NET
(NuGet)
May 11, 2026
ProTip!
Advisories are also available from the
GraphQL API