GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
132,036 advisories
Filter by severity
A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event...
High
Unreviewed
CVE-2026-12382
was published
Jul 15, 2026
Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in...
High
Unreviewed
CVE-2026-59776
was published
Jul 21, 2026
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the...
High
Unreviewed
CVE-2026-58016
was published
Jun 30, 2026
A post-authentication command injection vulnerability in the "LogServer" field of the syslog...
High
Unreviewed
CVE-2026-6952
was published
Jul 21, 2026
A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components()...
High
Unreviewed
CVE-2026-14476
was published
Jul 7, 2026
Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java...
High
Unreviewed
CVE-2026-56624
was published
Jul 20, 2026
Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who...
High
Unreviewed
CVE-2026-63728
was published
Jul 21, 2026
FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line...
High
Unreviewed
CVE-2026-64624
was published
Jul 21, 2026
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library...
High
Unreviewed
CVE-2026-56452
was published
Jul 20, 2026
A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not...
High
Unreviewed
CVE-2026-14474
was published
Jul 7, 2026
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow...
High
Unreviewed
CVE-2026-10649
was published
Jun 16, 2026
Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
High
CVE-2026-59205
was published
for
pillow
(pip)
Jul 20, 2026
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
High
CVE-2026-59204
was published
for
pillow
(pip)
Jul 20, 2026
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
High
CVE-2026-59200
was published
for
Pillow
(pip)
Jul 20, 2026
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
High
CVE-2026-59199
was published
for
Pillow
(pip)
Jul 20, 2026
Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
High
CVE-2026-59197
was published
for
Pillow
(pip)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
High
CVE-2026-50651
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability
High
CVE-2026-50525
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
High
CVE-2026-50528
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
High
CVE-2026-50648
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
High
CVE-2026-50524
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability
High
CVE-2026-47304
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
High
CVE-2026-47302
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
High
CVE-2026-57108
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
High
GHSA-gcfj-64vw-6mp9
was published
for
axios
(npm)
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API