GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
270 advisories
Filter by severity
OpenAM Insecure SSO Cookie Initialization
High
CVE-2026-53660
was published
for
org.openidentityplatform.openam:openam-core
(Maven)
Aug 14, 2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that...
Critical
Unreviewed
CVE-2025-59321
was published
Aug 12, 2026
The Windows installer deployed Npcap leaving its access restriction option at the insecure...
Moderate
Unreviewed
CVE-2026-33921
was published
Aug 11, 2026
Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with...
Moderate
Unreviewed
CVE-2026-63563
was published
Aug 3, 2026
Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the...
Moderate
Unreviewed
CVE-2026-62416
was published
Aug 3, 2026
Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is...
Critical
Unreviewed
CVE-2026-16503
was published
Jul 31, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Critical
CVE-2026-66066
was published
for
activestorage
(RubyGems)
Jul 30, 2026
Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote...
Moderate
Unreviewed
CVE-2026-9680
was published
Jul 28, 2026
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and ...
Low
Unreviewed
CVE-2026-55708
was published
Jul 22, 2026
The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated...
Critical
Unreviewed
CVE-2026-62415
was published
Jul 21, 2026
The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated...
Critical
Unreviewed
CVE-2026-60024
was published
Jul 17, 2026
Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod...
High
Unreviewed
CVE-2026-62185
was published
Jul 14, 2026
Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover
Critical
CVE-2026-52824
was published
for
kimai/kimai
(Composer)
Jul 14, 2026
PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the...
High
Unreviewed
CVE-2026-61439
was published
Jul 11, 2026
SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
Critical
CVE-2026-54158
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jul 10, 2026
SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
Critical
CVE-2026-54067
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jul 10, 2026
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
High
CVE-2026-54066
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jul 10, 2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions <...
Moderate
Unreviewed
CVE-2026-54800
was published
Jul 9, 2026
Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
High
GHSA-9h47-pqcx-hjr4
was published
for
better-auth
(npm)
Jul 7, 2026
A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not...
High
Unreviewed
CVE-2026-14474
was published
Jul 7, 2026
nono-py vulnerable to authorization bypass / policy confusion
Moderate
GHSA-9j7f-3r4p-pwh6
was published
for
nono-py
(pip)
Jun 26, 2026
OpenAM Authentication Bypass via MSISDN LDAP Injection
High
CVE-2026-46619
was published
for
org.openidentityplatform.openam:openam-auth-msisdn
(Maven)
Jun 26, 2026
MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies
Moderate
CVE-2026-48509
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
High
CVE-2026-48502
was published
for
MessagePack
(NuGet)
Jun 25, 2026
Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code...
Moderate
Unreviewed
CVE-2026-50519
was published
Jun 19, 2026
ProTip!
Advisories are also available from the
GraphQL API