GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
132,034 advisories
Filter by severity
A stack-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within a...
High
Unreviewed
CVE-2026-34122
was published
Apr 2, 2026
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome...
High
Unreviewed
CVE-2026-35385
was published
Apr 2, 2026
A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP...
High
Unreviewed
CVE-2026-34124
was published
Apr 2, 2026
A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the...
High
Unreviewed
CVE-2026-34120
was published
Apr 2, 2026
A security flaw has been discovered in Trendnet TEW-657BRM 1.00.1. The impacted element is the...
High
Unreviewed
CVE-2026-5350
was published
Apr 2, 2026
A vulnerability was identified in Trendnet TEW-657BRM 1.00.1. The affected element is the...
High
Unreviewed
CVE-2026-5349
was published
Apr 2, 2026
An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in...
High
Unreviewed
CVE-2026-34876
was published
Apr 2, 2026
A bug in POST request handling causes a crash under a certain condition.
This issue affects...
High
Unreviewed
CVE-2025-58136
was published
Apr 2, 2026
Apache Traffic Server allows request smuggling if chunked messages are malformed.
This issue...
High
Unreviewed
CVE-2025-65114
was published
Apr 2, 2026
A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in Balena Etcher for Windows...
High
Unreviewed
CVE-2026-30332
was published
Apr 2, 2026
Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via...
High
Unreviewed
CVE-2026-34790
was published
Apr 2, 2026
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS...
High
Unreviewed
CVE-2026-34794
was published
Apr 2, 2026
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS...
High
Unreviewed
CVE-2026-34796
was published
Apr 2, 2026
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS...
High
Unreviewed
CVE-2026-34793
was published
Apr 2, 2026
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS...
High
Unreviewed
CVE-2026-34791
was published
Apr 2, 2026
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS...
High
Unreviewed
CVE-2026-34797
was published
Apr 2, 2026
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS...
High
Unreviewed
CVE-2026-34792
was published
Apr 2, 2026
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS...
High
Unreviewed
CVE-2026-34795
was published
Apr 2, 2026
In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low...
High
Unreviewed
CVE-2026-3692
was published
Apr 2, 2026
A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an...
High
Unreviewed
CVE-2026-2737
was published
Apr 2, 2026
Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants
High
CVE-2026-4636
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 2, 2026
Keycloak: Application-Level DoS via Scope Processing
High
CVE-2026-4634
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 2, 2026
SzafirHost downloads necessary files in the context of the initiating web page. When called,...
High
Unreviewed
CVE-2026-26928
was published
Apr 2, 2026
Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw
High
CVE-2026-4282
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 2, 2026
Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint
High
CVE-2026-3872
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 2, 2026
ProTip!
Advisories are also available from the
GraphQL API