GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
533 advisories
Filter by severity
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
High
CVE-2026-52856
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
High
GHSA-26gq-p25f-99cp
was published
for
github.com/fatedier/frp
(Go)
Jul 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-af: CGX: add...
High
Unreviewed
CVE-2026-64225
was published
Jul 24, 2026
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
Moderate
GHSA-cqjc-rmpq-xprq
was published
for
russh
(Rust)
Jul 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
iio: adc: ti-ads1298: add...
High
Unreviewed
CVE-2026-53386
was published
Jul 19, 2026
In the Linux kernel, the following vulnerability has been resolved:
iio: light: veml6075: add...
High
Unreviewed
CVE-2026-53387
was published
Jul 19, 2026
Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the...
Moderate
Unreviewed
CVE-2026-63308
was published
Jul 17, 2026
NVIDIA TensorRT for contains a vulnerability where an attacker might cause an improper validation...
High
Unreviewed
CVE-2026-24238
was published
Jul 14, 2026
Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This...
High
Unreviewed
CVE-2026-15685
was published
Jul 14, 2026
GoBGP confederation validation panics on empty AS_PATH attribute
Moderate
CVE-2026-49838
was published
for
github.com/osrg/gobgp/v4
(Go)
Jul 9, 2026
The application opens a PDF, but the cloud-like appearance of the construction process lacks...
High
Unreviewed
CVE-2026-57251
was published
Jul 8, 2026
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
High
Unreviewed
CVE-2026-57272
was published
Jul 2, 2026
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
High
Unreviewed
CVE-2026-57271
was published
Jul 2, 2026
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
High
Unreviewed
CVE-2026-57270
was published
Jul 2, 2026
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
High
Unreviewed
CVE-2026-57268
was published
Jul 2, 2026
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
High
Unreviewed
CVE-2026-57265
was published
Jul 2, 2026
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
High
Unreviewed
CVE-2026-57264
was published
Jul 2, 2026
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
High
Unreviewed
CVE-2026-57266
was published
Jul 2, 2026
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
High
Unreviewed
CVE-2026-13131
was published
Jul 2, 2026
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
High
Unreviewed
CVE-2026-57267
was published
Jul 2, 2026
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
High
Unreviewed
CVE-2026-13132
was published
Jul 2, 2026
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
High
Unreviewed
CVE-2026-57269
was published
Jul 2, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts
Moderate
GHSA-3ccm-4qq2-5wrp
was published
for
github.com/edgelesssys/contrast
(Go)
Jul 1, 2026
DVP80ES300T with Improper Validation of Array Index Vulnerability
High
Unreviewed
CVE-2026-14193
was published
Jul 1, 2026
An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR ...
High
Unreviewed
CVE-2026-14191
was published
Jul 1, 2026
ProTip!
Advisories are also available from the
GraphQL API