GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,821
Maven
5,000+
npm
5,000+
NuGet
939
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
158,248 advisories
Filter by severity
mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport
Moderate
CVE-2026-0895
was published
for
cpsit/typo3-mailqueue
(Composer)
Jan 21, 2026
In the Linux kernel, the following vulnerability has been resolved:
net: sock: fix hardened...
Moderate
Unreviewed
CVE-2026-22977
was published
Jan 21, 2026
Denial-of-service vulnerability in M-Files Server versions before 26.1.15632.3 allows an...
Moderate
Unreviewed
CVE-2026-0663
was published
Jan 21, 2026
Keycloak services allows the issuance of access and refresh tokens for disabled users
Moderate
CVE-2025-14559
was published
for
org.keycloak:keycloak-services
(Maven)
Jan 21, 2026
In the Linux kernel, the following vulnerability has been resolved:
net/sched: sch_qfq: Fix NULL...
Moderate
Unreviewed
CVE-2026-22976
was published
Jan 21, 2026
ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load
Moderate
CVE-2026-23952
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jan 21, 2026
ImageMagick has a Memory Leak in LoadOpenCLDeviceBenchmark() when parsing malformed XML
Moderate
GHSA-qp59-x883-77qv
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jan 21, 2026
ImageMagick MSL: Stack overflow via infinite recursion in ProcessMSLScript
Moderate
CVE-2026-23874
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jan 21, 2026
Swift W3C TraceContext vulnerable to a malformed HTTP header causing a crash
Moderate
CVE-2026-23886
was published
for
github.com/swift-otel/swift-otel
(Swift)
Jan 21, 2026
AlchemyCMS: Authenticated Remote Code Execution (RCE) via eval injection in ResourcesHelper
Moderate
CVE-2026-23885
was published
for
alchemy_cms
(RubyGems)
Jan 21, 2026
ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component
Moderate
CVE-2026-23833
was published
for
esphome
(pip)
Jan 21, 2026
Swing Music has a Directory Traversal & Filesystem can be accessed by a non-admin user
Moderate
CVE-2026-23877
was published
for
swingmusic
(pip)
Jan 21, 2026
File Browser Vulnerable to Username Enumeration via Timing Attack in /api/login
Moderate
CVE-2026-23849
was published
for
github.com/filebrowser/filebrowser
(Go)
Jan 21, 2026
Mailpit has a Server-Side Request Forgery (SSRF) via HTML Check API
Moderate
CVE-2026-23845
was published
for
github.com/axllent/mailpit
(Go)
Jan 21, 2026
Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation
Moderate
CVE-2026-21852
was published
for
@anthropic-ai/claude-code
(npm)
Jan 21, 2026
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle...
Moderate
Unreviewed
CVE-2026-21944
was published
Jan 21, 2026
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services...
Moderate
Unreviewed
CVE-2026-21978
was published
Jan 21, 2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). ...
Moderate
Unreviewed
CVE-2026-21964
was published
Jan 21, 2026
Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality...
Moderate
Unreviewed
CVE-2026-21966
was published
Jan 21, 2026
Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion ...
Moderate
Unreviewed
CVE-2026-21979
was published
Jan 21, 2026
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). ...
Moderate
Unreviewed
CVE-2026-21963
was published
Jan 21, 2026
Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft ...
Moderate
Unreviewed
CVE-2026-21961
was published
Jan 21, 2026
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). ...
Moderate
Unreviewed
CVE-2026-21981
was published
Jan 21, 2026
Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences...
Moderate
Unreviewed
CVE-2026-21970
was published
Jan 21, 2026
Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component...
Moderate
Unreviewed
CVE-2026-21971
was published
Jan 21, 2026
ProTip!
Advisories are also available from the
GraphQL API