GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
316 advisories
Filter by severity
A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C,...
Low
Unreviewed
CVE-2026-19748
was published
Aug 13, 2026
Spring AMQP Has Predictable Correlation IDs in RabbitTemplate.sendAndReceive() with Fixed Reply Queue
Moderate
CVE-2026-41701
was published
for
org.springframework.amqp:spring-amqp
(Maven)
Jun 10, 2026
IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with...
Moderate
Unreviewed
CVE-2026-18531
was published
Aug 5, 2026
A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large...
Moderate
Unreviewed
CVE-2026-71225
was published
Aug 5, 2026
A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the...
Critical
Unreviewed
CVE-2021-20322
was published
Feb 19, 2022
Spring Framework Predictable Session ID in WebSocket Module
Moderate
CVE-2026-41838
was published
for
org.springframework:spring-websocket
(Maven)
Jun 9, 2026
Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket....
Moderate
Unreviewed
CVE-2026-66391
was published
Jul 27, 2026
AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle
Moderate
CVE-2026-47703
was published
for
github.com/AdguardTeam/AdGuardHome
(Go)
Jun 4, 2026
Net::BitTorrent versions through 2.0.1 for Perl generate the MSE Diffie-Hellman private key with...
Moderate
Unreviewed
CVE-2026-57082
was published
Jun 30, 2026
Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection
Low
GHSA-gq4g-fpc9-vjfq
was published
for
web-auth/webauthn-lib
(Composer)
Jul 7, 2026
Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased...
High
Unreviewed
CVE-2026-14570
was published
Jul 5, 2026
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9...
Critical
Unreviewed
CVE-2022-36536
was published
Sep 17, 2022
Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to...
Moderate
Unreviewed
CVE-2022-29330
was published
Jun 25, 2022
RabbitMQ has predictable credential obfuscation seed value used in Shovel and Federation plugins
Moderate
CVE-2022-31008
was published
for
rabbit_common
(Erlang)
Jun 30, 2026
Netty: QUIC stateless reset token material exposed through header-visible connection IDs
Moderate
CVE-2026-50009
was published
for
io.netty:netty-codec-classes-quic
(Maven)
Jun 15, 2026
Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
Moderate
CVE-2026-45673
was published
for
io.netty:netty-resolver-dns
(Maven)
Jun 8, 2026
netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failures
Moderate
CVE-2026-41207
was published
for
io.netty.incubator:netty-incubator-codec-ohttp
(Maven)
May 26, 2026
Vantage6 Server JWT secret not cryptographically secure
Low
CVE-2025-43866
was published
for
vantage6-server
(pip)
Jun 12, 2025
Gradio has an Open Redirect in its OAuth Flow
Moderate
CVE-2026-28415
was published
for
gradio
(pip)
Mar 1, 2026
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard...
Critical
Unreviewed
CVE-2026-50208
was published
Jun 4, 2026
dasdec_mkuser on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe...
High
Unreviewed
CVE-2013-4734
was published
May 17, 2022
Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro II version 1.17478...
Critical
Unreviewed
CVE-2025-13955
was published
Dec 10, 2025
ImageMagick: Information Disclosure in PasskeyEncipherImage via AES-CTR nonce reuse
Low
GHSA-qv2q-c278-pch5
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 21, 2026
Netatalk 2.0.0 through 4.4.2 generates AFP session tokens derived from predictable process IDs,...
Moderate
Unreviewed
CVE-2026-44054
was published
May 21, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
CVE-2026-42155
was published
for
openmage/magento-lts
(Composer)
May 5, 2026
ProTip!
Advisories are also available from the
GraphQL API