GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,517
Rust
20
52 advisories
Filter by severity
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in...
Moderate
Unreviewed
CVE-2025-11703
was published
Oct 18, 2025
An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in...
Low
Unreviewed
CVE-2025-1680
was published
Oct 23, 2025
A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in...
High
Unreviewed
CVE-2025-5994
was published
Jul 16, 2025
AsyncSSH Rogue Extension Negotiation
Moderate
CVE-2023-46445
was published
for
asyncssh
(pip)
Nov 9, 2023
Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an...
High
Unreviewed
CVE-2025-40778
was published
Oct 22, 2025
NLnet Labs Unbound up to and including version 1.24.0 is vulnerable to possible domain hijack...
Moderate
Unreviewed
CVE-2025-11411
was published
Oct 22, 2025
In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote...
Moderate
Unreviewed
CVE-2025-68269
was published
Dec 16, 2025
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport...
High
Unreviewed
CVE-2026-1642
was published
Feb 4, 2026
OpenClaw has an Arbitrary Malicious Code Execution Vulnerability
High
CVE-2026-35641
was published
for
openclaw
(npm)
Mar 30, 2026
Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized...
High
Unreviewed
CVE-2026-32162
was published
Apr 14, 2026
OpenClaw: Zalo replay dedupe keys could suppress messages across chats or senders
Moderate
CVE-2026-41354
was published
for
openclaw
(npm)
Apr 7, 2026
Next.js's Middleware / Proxy redirects can be cache-poisoned
Low
CVE-2026-44572
was published
for
next
(npm)
May 11, 2026
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous...
Moderate
Unreviewed
CVE-2026-42960
was published
May 20, 2026
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering...
Critical
Unreviewed
CVE-2026-45602
was published
Jun 9, 2026
A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads...
High
Unreviewed
CVE-2026-33612
was published
Jun 25, 2026
Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous...
Critical
Unreviewed
CVE-2026-41120
was published
Jun 25, 2026
gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
High
CVE-2026-40034
was published
for
gix
(Rust)
May 5, 2026
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
Low
CVE-2026-46342
was published
for
@nuxt/nitro-server
(npm)
May 19, 2026
In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and...
Moderate
Unreviewed
CVE-2026-50252
was published
Jul 22, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
Moderate
CVE-2026-54625
was published
for
django-cms
(pip)
Aug 24, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2...
Moderate
Unreviewed
CVE-2026-15387
was published
Aug 26, 2026
The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related...
Moderate
Unreviewed
CVE-2026-74916
was published
Sep 1, 2026
A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone...
Moderate
Unreviewed
CVE-2026-78301
was published
Sep 16, 2026
For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data...
Moderate
Unreviewed
CVE-2026-19033
was published
Sep 16, 2026
ProTip!
Advisories are also available from the
GraphQL API