GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
132,034 advisories
Filter by severity
In the Linux kernel, the following vulnerability has been resolved:
futex: Fix UaF between...
High
Unreviewed
CVE-2026-23415
was published
Apr 2, 2026
In the Linux kernel, the following vulnerability has been resolved:
netfilter: bpf: defer hook...
High
Unreviewed
CVE-2026-23412
was published
Apr 2, 2026
In the Linux kernel, the following vulnerability has been resolved:
clsact: Fix use-after-free...
High
Unreviewed
CVE-2026-23413
was published
Apr 2, 2026
Due to the improper neutralisation of special elements used in an OS command, a remote attacker...
High
Unreviewed
CVE-2026-33613
was published
Apr 2, 2026
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in...
High
Unreviewed
CVE-2026-33614
was published
Apr 2, 2026
An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection...
High
Unreviewed
CVE-2026-33616
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner...
High
Unreviewed
CVE-2026-29143
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA...
High
Unreviewed
CVE-2026-29139
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker...
High
Unreviewed
CVE-2026-29140
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject...
High
Unreviewed
CVE-2026-29144
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject...
High
Unreviewed
CVE-2026-29141
was published
Apr 2, 2026
Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows local apps to...
High
Unreviewed
CVE-2026-0634
was published
Apr 2, 2026
The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions...
High
Unreviewed
CVE-2026-0686
was published
Apr 2, 2026
The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up...
High
Unreviewed
CVE-2026-5032
was published
Apr 2, 2026
The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient...
High
Unreviewed
CVE-2026-4347
was published
Apr 2, 2026
The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file,...
High
Unreviewed
CVE-2026-1540
was published
Apr 2, 2026
V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6MemInIF...
High
Unreviewed
CVE-2026-32927
was published
Apr 2, 2026
V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read in VS6ComFile!get_macro_mem_COM....
High
Unreviewed
CVE-2026-32929
was published
Apr 2, 2026
V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6ComFile...
High
Unreviewed
CVE-2026-32926
was published
Apr 2, 2026
V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData:...
High
Unreviewed
CVE-2026-32928
was published
Apr 2, 2026
V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CV7BaseMap:...
High
Unreviewed
CVE-2026-32925
was published
Apr 2, 2026
A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow...
High
Unreviewed
CVE-2026-3987
was published
Apr 2, 2026
HCL BigFix Platform is affected by insecure permissions on private cryptographic keys. The...
High
Unreviewed
CVE-2026-21765
was published
Apr 2, 2026
mcp-handler has a tool response leak across concurrent client sessions ('Race Condition')
High
GHSA-w2fm-25vw-vh7f
was published
for
mcp-handler
(npm)
Apr 1, 2026
EnhancedLinq.Async is Vulnerable to Denial of Service via Transitive Dependency Microsoft.Bcl.Memory
High
GHSA-32wq-ppwg-3w4m
was published
for
EnhancedLinq.Async
(NuGet)
Apr 1, 2026
ProTip!
Advisories are also available from the
GraphQL API