GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,340
Maven
5,000+
npm
5,000+
NuGet
1,033
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
131,737 advisories
Filter by severity
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2026-3457
was published
Mar 27, 2026
Doveadm credentials are verified using direct comparison which is susceptible to timing oracle...
High
Unreviewed
CVE-2026-27856
was published
Mar 27, 2026
Attacker can send a specifically crafted message before authentication that causes managesieve to...
High
Unreviewed
CVE-2026-27858
was published
Mar 27, 2026
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin....
High
Unreviewed
CVE-2026-24031
was published
Mar 27, 2026
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be...
High
Unreviewed
CVE-2025-59032
was published
Mar 27, 2026
Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker...
High
Unreviewed
CVE-2026-32678
was published
Mar 27, 2026
Spring AI Redis Store has TAG Field Query Injection Through Improper Neutralization of Special Characters
High
CVE-2026-22744
was published
for
org.springframework.ai:spring-ai-redis-store
(Maven)
Mar 27, 2026
Spring AI has a Cypher Injection vulnerability in Neo4jVectorFilterExpressionConverter
High
CVE-2026-22743
was published
for
org.springframework.ai:spring-ai-neo4j-store
(Maven)
Mar 27, 2026
OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability...
High
Unreviewed
CVE-2026-27650
was published
Mar 27, 2026
Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is...
High
Unreviewed
CVE-2026-32669
was published
Mar 27, 2026
Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker...
High
Unreviewed
CVE-2026-33280
was published
Mar 27, 2026
Spring AI: Insufficient Validation causes SSRF when processing multimodal messages with user-supplied URLs
High
CVE-2026-22742
was published
for
org.springframework.ai:spring-ai-bedrock-converse
(Maven)
Mar 27, 2026
A vulnerability was determined in Tenda AC5 15.03.06.47. The affected element is the function...
High
Unreviewed
CVE-2026-4906
was published
Mar 27, 2026
A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing...
High
Unreviewed
CVE-2026-3650
was published
Mar 27, 2026
In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate...
High
Unreviewed
CVE-2026-34352
was published
Mar 27, 2026
A vulnerability was detected in Tenda AC5 15.03.06.47. This affects the function fromAddressNat...
High
Unreviewed
CVE-2026-4902
was published
Mar 27, 2026
A vulnerability was found in Tenda AC5 15.03.06.47. Impacted is the function formWifiWpsOOB of...
High
Unreviewed
CVE-2026-4905
was published
Mar 27, 2026
A vulnerability has been found in Tenda AC5 15.03.06.47. This issue affects the function...
High
Unreviewed
CVE-2026-4904
was published
Mar 27, 2026
A flaw has been found in Tenda AC5 15.03.06.47. This vulnerability affects the function...
High
Unreviewed
CVE-2026-4903
was published
Mar 27, 2026
Grafana Tempo has Inadequate Encryption Strength
High
CVE-2026-28377
was published
for
github.com/grafana/tempo
(Go)
Mar 27, 2026
A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows...
High
Unreviewed
CVE-2025-12805
was published
Mar 27, 2026
C2C CI utils is vulnerable to DoS via pyasn dependency (CVE-2026-30922)
High
GHSA-wcjx-v2wj-xg87
was published
for
c2cciutils
(pip)
Mar 26, 2026
Happy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable code
High
CVE-2026-33943
was published
for
happy-dom
(npm)
Mar 26, 2026
Ella Core has Privilege Escalation via Database Restore by NetworkManager role
High
CVE-2026-33906
was published
for
github.com/ellanetworks/core
(Go)
Mar 26, 2026
Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)
High
CVE-2026-33896
was published
for
node-forge
(npm)
Mar 26, 2026
ProTip!
Advisories are also available from the
GraphQL API