GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,821
Maven
5,000+
npm
5,000+
NuGet
939
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
158,248 advisories
Filter by severity
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9.1 before 18.9.7,...
Moderate
Unreviewed
CVE-2026-4524
was published
May 14, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.9.7,...
Moderate
Unreviewed
CVE-2026-4527
was published
May 14, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18...
Moderate
Unreviewed
CVE-2026-1322
was published
May 14, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.9.7, 18...
Moderate
Unreviewed
CVE-2026-3607
was published
May 14, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.9.7, 18...
Moderate
Unreviewed
CVE-2026-3074
was published
May 14, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 18.9.7, 18...
Moderate
Unreviewed
CVE-2026-3073
was published
May 14, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18...
Moderate
Unreviewed
CVE-2026-3160
was published
May 14, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10...
Moderate
Unreviewed
CVE-2026-1184
was published
May 14, 2026
The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site...
Moderate
Unreviewed
CVE-2025-15345
was published
May 14, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.9.7,...
Moderate
Unreviewed
CVE-2026-1338
was published
May 14, 2026
The GLS Shipping for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site...
Moderate
Unreviewed
CVE-2026-6417
was published
May 14, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 18.9.7, 18...
Moderate
Unreviewed
CVE-2026-6063
was published
May 14, 2026
The Envira Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2026-5361
was published
May 14, 2026
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the ...
Moderate
Unreviewed
CVE-2026-5486
was published
May 14, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7,...
Moderate
Unreviewed
CVE-2025-12669
was published
May 14, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18...
Moderate
Unreviewed
CVE-2025-13874
was published
May 14, 2026
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-7648
was published
May 14, 2026
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to authorization...
Moderate
Unreviewed
CVE-2026-7525
was published
May 14, 2026
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in...
Moderate
Unreviewed
CVE-2026-44919
was published
May 14, 2026
Android App "あんしんフィルター for au" provided by KDDI CORPORATION contains Cleartext Transmission of...
Moderate
Unreviewed
CVE-2026-41281
was published
May 14, 2026
Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System...
Moderate
Unreviewed
CVE-2026-45228
was published
May 13, 2026
The ftpcp() function in Lib/ftplib.py was not updated when
CVE-2021-4189 was fixed. While...
Moderate
Unreviewed
CVE-2026-8328
was published
May 13, 2026
Editors could delete any annotation, even those they do not have read access to. The editor user...
Moderate
Unreviewed
CVE-2026-28374
was published
May 13, 2026
A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server...
Moderate
Unreviewed
CVE-2026-28379
was published
May 13, 2026
Any Editor could delete any snapshot, even if they have no access to read or write them.
Moderate
Unreviewed
CVE-2026-28380
was published
May 13, 2026
ProTip!
Advisories are also available from the
GraphQL API