GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
31 advisories
Filter by severity
TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99.
...
Critical
Unreviewed
CVE-2026-16634
was published
Jul 24, 2026
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware ...
High
Unreviewed
CVE-2026-60368
was published
Jul 23, 2026
HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may...
Low
Unreviewed
CVE-2026-56580
was published
Jul 21, 2026
Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library.
...
Critical
Unreviewed
CVE-2026-3031
was published
Jul 16, 2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework...
High
Unreviewed
CVE-2023-37524
was published
Jun 27, 2026
The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious...
Moderate
Unreviewed
CVE-2024-23581
was published
Jun 26, 2026
The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x...
High
Unreviewed
CVE-2026-21821
was published
May 13, 2026
Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known...
Critical
Unreviewed
CVE-2026-41468
was published
Apr 22, 2026
HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which...
Low
Unreviewed
CVE-2025-55277
was published
Mar 26, 2026
Use of unmaintained third party components for some Intel(R) Processor Identification Utility...
High
Unreviewed
CVE-2025-20010
was published
Nov 11, 2025
The device is running an outdated operating system, which may be susceptible to known...
Critical
Unreviewed
CVE-2025-10561
was published
Oct 27, 2025
Outdated and Vulnerable UI Dependencies might potentially lead to exploitation.This issue affects...
Critical
Unreviewed
CVE-2025-12104
was published
Oct 23, 2025
HCL MyXalytics
6.6. product is affected by Use of Vulnerable/Outdated Versions Vulnerability
Low
Unreviewed
CVE-2025-52658
was published
Oct 3, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.893 and...
Critical
Unreviewed
CVE-2025-34192
was published
Sep 19, 2025
Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in...
Critical
Unreviewed
CVE-2025-10220
was published
Sep 10, 2025
The Linux distribution underlying the Radiflow iSAP Smart Collector
(CentOS 7 - VSAP 1.20) is...
High
Unreviewed
CVE-2025-3497
was published
Jul 9, 2025
BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several...
Critical
Unreviewed
CVE-2025-40906
was published
May 16, 2025
This CVE has been issued to inform users that they are using End-of-Life (EOL) versions of Node...
High
Unreviewed
CVE-2025-23088
was published
Jan 22, 2025
This CVE has been issued to inform users that they are using End-of-Life (EOL) versions of Node...
High
Unreviewed
CVE-2025-23089
was published
Jan 22, 2025
This CVE has been issued to inform users that they are using End-of-Life (EOL) versions of Node...
High
Unreviewed
CVE-2025-23087
was published
Jan 22, 2025
CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause...
High
Unreviewed
CVE-2024-11999
was published
Dec 17, 2024
A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device...
High
Unreviewed
CVE-2024-8885
was published
Oct 2, 2024
Azure Storage Movement Client Library Denial of Service Vulnerability
High
CVE-2024-35252
was published
for
Microsoft.Azure.Storage.DataMovement
(NuGet)
Jun 11, 2024
Vapor contains an integer overflow in URI leading to potential host spoofing
Moderate
CVE-2024-21631
was published
for
github.com/vapor/vapor
(Swift)
Jan 3, 2024
Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG...
Critical
Unreviewed
CVE-2023-7102
was published
Dec 25, 2023
ProTip!
Advisories are also available from the
GraphQL API