GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
132,662 advisories
Filter by severity
A low privileged remote attacker can gain the root password due to improper removal of sensitive...
High
Unreviewed
CVE-2024-43384
was published
May 7, 2026
OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual...
High
Unreviewed
CVE-2025-9661
was published
May 7, 2026
Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in...
High
Unreviewed
CVE-2025-1978
was published
May 7, 2026
The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the ...
High
Unreviewed
CVE-2026-4348
was published
May 7, 2026
The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0...
High
Unreviewed
CVE-2026-6692
was published
May 7, 2026
The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed &...
High
Unreviewed
CVE-2026-7252
was published
May 7, 2026
An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty...
High
Unreviewed
CVE-2026-8063
was published
May 7, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints
High
CVE-2026-34403
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Apr 21, 2026
Bandit Buffers Unbounded WebSocket Continuation Frames, Allowing Unauthenticated Memory Exhaustion
High
CVE-2026-42786
was published
for
bandit
(Erlang)
May 7, 2026
Bandit's unbounded WebSocket inflate causes BEAM OOM with a single frame
High
CVE-2026-39804
was published
for
bandit
(Erlang)
May 7, 2026
In the Linux kernel, the following vulnerability has been resolved:
ALSA: ctxfi: Fix missing...
High
Unreviewed
CVE-2026-31776
was published
May 1, 2026
In the Linux kernel, the following vulnerability has been resolved:
io_uring/net: fix slab-out...
High
Unreviewed
CVE-2026-31774
was published
May 1, 2026
Insecure preserved inherited permissions vulnerability in Cerberus FTP Server on Windows allows...
High
Unreviewed
CVE-2026-6265
was published
Apr 27, 2026
hickory-proto: NSEC3 closest-encloser proof validation enters unbounded loop on cross-zone responses
High
GHSA-3v94-mw7p-v465
was published
for
hickory-net
(Rust)
May 7, 2026
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization
High
CVE-2026-42402
was published
for
org.apache.neethi:neethi
(Maven)
May 1, 2026
Apache Neethi does not properly detect circular references in policy definitions.
High
CVE-2026-42403
was published
for
org.apache.neethi:neethi
(Maven)
May 1, 2026
rust-zserio has Unbounded Memory Allocation
High
GHSA-fpf5-4jw8-67x8
was published
for
rust-zserio
(Rust)
May 7, 2026
Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure
High
GHSA-fc67-c4hg-q653
was published
for
github.com/aws/amazon-ecs-agent
(Go)
May 7, 2026
Krayin CRM allows a remote attacker to execute arbitrary code via compose email function
High
CVE-2026-36340
was published
for
krayin/laravel-crm
(Composer)
Apr 30, 2026
Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96...
High
Unreviewed
CVE-2026-8007
was published
May 6, 2026
Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to...
High
Unreviewed
CVE-2026-8016
was published
May 6, 2026
Insufficient validation of untrusted input in UI in Google Chrome on Linux, ChromeOS prior to 148...
High
Unreviewed
CVE-2026-7992
was published
May 6, 2026
Inappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96...
High
Unreviewed
CVE-2026-7994
was published
May 6, 2026
Out of bounds read in AdFilter in Google Chrome prior to 148.0.7778.96 allowed a remote attacker...
High
Unreviewed
CVE-2026-7995
was published
May 6, 2026
Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced...
High
Unreviewed
CVE-2026-7976
was published
May 6, 2026
ProTip!
Advisories are also available from the
GraphQL API