GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
812 advisories
Filter by severity
A flaw was found in the signature verification logic of noobaa-core, the core component of the...
High
Unreviewed
CVE-2026-94368
was published
Sep 21, 2026
The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper...
Moderate
Unreviewed
CVE-2026-9832
was published
Sep 19, 2026
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
Critical
CVE-2026-59163
was published
for
mnemosyne-memory
(pip)
Sep 18, 2026
hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the...
High
Unreviewed
CVE-2026-93657
was published
Sep 18, 2026
An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell...
Critical
Unreviewed
CVE-2026-28198
was published
Sep 18, 2026
An authenticated user with access to the NetBackup Flex OS management
shell could read arbitrary...
Moderate
Unreviewed
CVE-2026-28199
was published
Sep 18, 2026
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
High
CVE-2026-86038
was published
for
@libp2p/gossipsub
(npm)
Sep 17, 2026
Nuclei versions before 3.11.1 cache template signature verification based only on file...
High
Unreviewed
CVE-2026-92718
was published
Sep 16, 2026
A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older...
High
Unreviewed
CVE-2026-42784
was published
Sep 16, 2026
The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors,...
High
Unreviewed
CVE-2026-86585
was published
Sep 16, 2026
The VeloCloud Edge software update workflow may accept update bundles without properly validating...
High
Unreviewed
CVE-2026-86109
was published
Sep 16, 2026
Improper verification of cryptographic signature vulnerability in Apache Syncope.
When SRA is...
Critical
Unreviewed
CVE-2026-87802
was published
Sep 14, 2026
An attacker may achieve arbitrary code execution on a target system by uploading a malicious...
High
Unreviewed
CVE-2026-80469
was published
Sep 11, 2026
A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML...
High
Unreviewed
CVE-2026-73784
was published
Sep 11, 2026
live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection...
Moderate
Unreviewed
CVE-2026-89169
was published
Sep 11, 2026
In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only...
Critical
Unreviewed
CVE-2026-89086
was published
Sep 10, 2026
n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
Moderate
CVE-2026-86080
was published
for
n8n
(npm)
Sep 10, 2026
passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an...
Critical
Unreviewed
CVE-2026-89042
was published
Sep 10, 2026
passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where...
Critical
Unreviewed
CVE-2026-89043
was published
Sep 10, 2026
PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that the identityPublicKey in...
High
Unreviewed
CVE-2023-54355
was published
Sep 9, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
Moderate
Unreviewed
CVE-2026-79970
was published
Sep 9, 2026
Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2...
Critical
Unreviewed
CVE-2026-56207
was published
Sep 9, 2026
An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM...
Moderate
Unreviewed
CVE-2026-87732
was published
Sep 9, 2026
An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify...
Moderate
Unreviewed
CVE-2026-52486
was published
Sep 8, 2026
Improper verification of cryptographic signature in Skype for Business allows an unauthorized...
High
Unreviewed
CVE-2026-69646
was published
Sep 8, 2026
ProTip!
Advisories are also available from the
GraphQL API