GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,340
Maven
5,000+
npm
5,000+
NuGet
1,033
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
131,737 advisories
Filter by severity
A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment ...
High
Unreviewed
CVE-2026-51082
was published
Jul 17, 2026
Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled.
The...
High
Unreviewed
CVE-2026-13410
was published
Jul 17, 2026
ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes...
High
Unreviewed
CVE-2026-57860
was published
Jul 17, 2026
An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 ...
High
Unreviewed
CVE-2026-9587
was published
Jul 17, 2026
A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 ...
High
Unreviewed
CVE-2026-9588
was published
Jul 17, 2026
An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox...
High
Unreviewed
CVE-2026-9585
was published
Jul 17, 2026
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution...
High
Unreviewed
CVE-2026-9762
was published
Jul 17, 2026
Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low...
High
Unreviewed
CVE-2026-63100
was published
Jul 17, 2026
Chat2DB before 5.3.0 contains an insecure direct object reference vulnerability in the GET /api...
High
Unreviewed
CVE-2026-63307
was published
Jul 17, 2026
Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client...
High
Unreviewed
CVE-2026-63095
was published
Jul 17, 2026
Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows...
High
Unreviewed
CVE-2026-63101
was published
Jul 17, 2026
TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the...
High
Unreviewed
CVE-2026-63099
was published
Jul 17, 2026
osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading...
High
Unreviewed
CVE-2026-14871
was published
Jul 17, 2026
Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video...
High
Unreviewed
CVE-2026-12691
was published
Jul 17, 2026
The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability.
High
Unreviewed
CVE-2026-58148
was published
Jul 17, 2026
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an...
High
Unreviewed
CVE-2026-15343
was published
Jul 17, 2026
Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google...
High
Unreviewed
CVE-2026-12715
was published
Jul 17, 2026
PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\....
High
Unreviewed
CVE-2026-57919
was published
Jun 29, 2026
Unauthorized File Access in node-git-server
High
GHSA-cv3v-7846-6pxm
was published
for
node-git-server
(npm)
Sep 3, 2020
Thelia authentication bypass vulnerability
High
GHSA-g8pg-33v4-9r96
was published
for
thelia/thelia
(Composer)
May 30, 2024
vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
High
CVE-2026-55574
was published
for
vllm
(pip)
Jul 17, 2026
vLLM has Remote DoS via Invalid Recovered Token Reinjection
High
CVE-2026-54234
was published
for
vllm
(pip)
Jul 17, 2026
Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials
High
CVE-2026-50136
was published
for
@budibase/server
(npm)
Jun 22, 2026
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
High
GHSA-g5r6-gv6m-f5jv
was published
for
mcp-atlassian
(pip)
Jul 10, 2026
ProTip!
Advisories are also available from the
GraphQL API