GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,340
Maven
5,000+
npm
5,000+
NuGet
1,033
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
131,737 advisories
Filter by severity
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: KVM: Handle the...
High
Unreviewed
CVE-2026-31569
was published
Apr 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
futex: Require...
High
Unreviewed
CVE-2026-31554
was published
Apr 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix fence put...
High
Unreviewed
CVE-2026-31566
was published
Apr 24, 2026
A vulnerability was found in Samba where a delegated administrator with permission to create...
High
Unreviewed
CVE-2020-25720
was published
Nov 17, 2024
Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7...
High
Unreviewed
CVE-2026-26354
was published
Apr 22, 2026
An integer overflow existed in the wolfCrypt CMAC implementation, that could be exploited to...
High
Unreviewed
CVE-2026-5477
was published
Apr 10, 2026
ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path traversal vulnerability in the...
High
Unreviewed
CVE-2026-41463
was published
Apr 27, 2026
A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects...
High
Unreviewed
CVE-2026-7138
was published
Apr 27, 2026
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is...
High
Unreviewed
CVE-2026-7136
was published
Apr 27, 2026
A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function...
High
Unreviewed
CVE-2026-7139
was published
Apr 27, 2026
A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This affects...
High
Unreviewed
CVE-2026-7137
was published
Apr 27, 2026
A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
High
Unreviewed
CVE-2026-7140
was published
Apr 27, 2026
Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before...
High
Unreviewed
CVE-2026-38934
was published
Apr 27, 2026
The Fan Control application V251 contains an improper privilege handling vulnerability in its...
High
Unreviewed
CVE-2025-69689
was published
Apr 27, 2026
ProjeQtor versions 7.0 through 12.4.3 contains a path traversal vulnerability in the log file...
High
Unreviewed
CVE-2026-41465
was published
Apr 27, 2026
ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the...
High
Unreviewed
CVE-2026-41464
was published
Apr 27, 2026
A path traversal vulnerability in the UI/static component of leonvanzyl autocoder commit 79d02a...
High
Unreviewed
CVE-2026-30351
was published
Apr 27, 2026
wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM...
High
Unreviewed
CVE-2026-5500
was published
Apr 10, 2026
wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which...
High
Unreviewed
CVE-2026-5501
was published
Apr 10, 2026
CWE-416: Use After Free vulnerability that could cause remote code execution when the end user...
High
Unreviewed
CVE-2025-13845
was published
Jan 15, 2026
PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling
High
CVE-2026-24765
was published
for
phpunit/phpunit
(Composer)
Jan 27, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access
High
CVE-2026-40885
was published
for
github.com/patrickhener/goshs/v2
(Go)
Apr 14, 2026
SFTP root escape via prefix-based path validation in goshs
High
CVE-2026-40876
was published
for
github.com/patrickhener/goshs
(Go)
Apr 14, 2026
Authentication Bypass in extension "E-Mail MFA Provider" (mfa_email)
High
CVE-2026-4208
was published
for
ralffreit/mfa-email
(Composer)
Mar 17, 2026
Juju has a resource poisoning vulnerability
High
CVE-2025-68153
was published
for
github.com/juju/juju
(Go)
Apr 3, 2026
ProTip!
Advisories are also available from the
GraphQL API