GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
643 advisories
Filter by severity
The web
interface of the affected
device relies on the HTTP referrer header as part of
request...
Moderate
Unreviewed
CVE-2026-15141
was published
Aug 13, 2026
The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys...
Moderate
Unreviewed
CVE-2026-18676
was published
Aug 12, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials...
High
Unreviewed
CVE-2026-18847
was published
Aug 12, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive...
High
Unreviewed
CVE-2026-18098
was published
Aug 12, 2026
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized...
High
Unreviewed
CVE-2026-56179
was published
Aug 11, 2026
The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became...
High
Unreviewed
CVE-2026-19418
was published
Aug 11, 2026
Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability...
High
Unreviewed
CVE-2026-66732
was published
Aug 6, 2026
Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on...
Critical
Unreviewed
CVE-2026-15587
was published
Aug 5, 2026
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity...
High
Unreviewed
CVE-2026-16442
was published
Aug 5, 2026
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
Moderate
CVE-2026-70599
was published
for
electron
(npm)
Aug 5, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2026-66317
was published
Aug 4, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-66318
was published
Aug 4, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2026-66316
was published
Aug 4, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-66322
was published
Aug 4, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2026-66313
was published
Aug 4, 2026
Guzzle: Noncanonical cookie domain keeps subdomain scope
Moderate
CVE-2026-69245
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that...
High
Unreviewed
CVE-2026-66420
was published
Jul 31, 2026
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
Moderate
CVE-2026-63118
was published
for
mcp
(RubyGems)
Jul 30, 2026
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-18016
was published
Jul 30, 2026
Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a...
Low
Unreviewed
CVE-2026-17997
was published
Jul 30, 2026
Insufficient policy enforcement in USB in Google Chrome on Android prior to 151.0.7922.72 allowed...
Low
Unreviewed
CVE-2026-18000
was published
Jul 30, 2026
Inappropriate implementation in Browser in Google Chrome on Android prior to 151.0.7922.72...
Low
Unreviewed
CVE-2026-17984
was published
Jul 30, 2026
Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote...
Moderate
Unreviewed
CVE-2026-17981
was published
Jul 30, 2026
Inappropriate implementation in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote...
Moderate
Unreviewed
CVE-2026-17963
was published
Jul 30, 2026
Policy bypass in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak...
Moderate
Unreviewed
CVE-2026-17977
was published
Jul 30, 2026
ProTip!
Advisories are also available from the
GraphQL API