GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
132,663 advisories
Filter by severity
mcp-ssh-tool has file transfer path policy bypass and bearer token comparison hardening
High
GHSA-j7h9-2jh7-g967
was published
for
mcp-ssh-tool
(npm)
May 7, 2026
ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI
High
GHSA-fpw6-hrg5-q5x5
was published
for
github.com/lin-snow/Ech0
(Go)
May 7, 2026
Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In...
High
Unreviewed
CVE-2026-42469
was published
May 1, 2026
In the Linux kernel, the following vulnerability has been resolved:
net: mana: fix use-after...
High
Unreviewed
CVE-2026-43056
was published
May 1, 2026
In the Linux kernel, the following vulnerability has been resolved:
HID: logitech-hidpp: Prevent...
High
Unreviewed
CVE-2026-43049
was published
May 1, 2026
Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In...
High
Unreviewed
CVE-2026-42468
was published
May 1, 2026
In the Linux kernel, the following vulnerability has been resolved:
net: macb: fix clk handling...
High
Unreviewed
CVE-2026-43015
was published
May 1, 2026
In the Linux kernel, the following vulnerability has been resolved:
reset: gpio: fix double free...
High
Unreviewed
CVE-2026-31745
was published
May 1, 2026
In the Linux kernel, the following vulnerability has been resolved:
comedi: me_daq: Fix...
High
Unreviewed
CVE-2026-31748
was published
May 1, 2026
In the Linux kernel, the following vulnerability has been resolved:
accel/qaic: Handle DBC...
High
Unreviewed
CVE-2026-43007
was published
May 1, 2026
In the Linux kernel, the following vulnerability has been resolved:
comedi: me4000: Fix...
High
Unreviewed
CVE-2026-31747
was published
May 1, 2026
An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624...
High
Unreviewed
CVE-2025-65857
was published
Dec 23, 2025
Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft
High
GHSA-p64j-f4x9-wq66
was published
for
github.com/lin-snow/Ech0
(Go)
May 7, 2026
Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the...
High
Unreviewed
CVE-2026-33589
was published
May 7, 2026
Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the...
High
Unreviewed
CVE-2026-33588
was published
May 7, 2026
An improper input validation, together with an overly permissive default CORS configuration in...
High
Unreviewed
CVE-2026-28201
was published
May 7, 2026
An issue was discovered in Vanetza V2X v26.02 allowing remote unauthorized attackers to cause a...
High
Unreviewed
CVE-2026-37554
was published
May 1, 2026
In the Linux kernel, the following vulnerability has been resolved:
bpf: sockmap: Fix use-after...
High
Unreviewed
CVE-2026-43016
was published
May 1, 2026
In the Linux kernel, the following vulnerability has been resolved:
nvmem: zynqmp_nvmem: Fix...
High
Unreviewed
CVE-2026-31743
was published
May 1, 2026
In the Linux kernel, the following vulnerability has been resolved:
HID: core: Mitigate...
High
Unreviewed
CVE-2026-43048
was published
May 1, 2026
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: idxd: Fix...
High
Unreviewed
CVE-2026-31442
was published
Apr 22, 2026
In the Linux kernel, the following vulnerability has been resolved:
crypto: tegra - Add missing...
High
Unreviewed
CVE-2026-31739
was published
May 1, 2026
Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation...
High
Unreviewed
CVE-2025-12690
was published
Mar 11, 2026
Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo
High
GHSA-8mc6-xjpr-h98x
was published
for
github.com/lin-snow/ech0
(Go)
May 7, 2026
FacturaScripts Vulnerable to Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism
High
CVE-2026-27891
was published
for
facturascripts/facturascripts
(Composer)
May 7, 2026
ProTip!
Advisories are also available from the
GraphQL API