GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,517
Rust
20
262 advisories
Filter by severity
Improper verification of cryptographic signature vulnerability in Apache APISIX.
Any...
Moderate
Unreviewed
CVE-2026-94212
was published
Oct 1, 2026
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 fail to...
Moderate
Unreviewed
CVE-2026-103245
was published
Oct 1, 2026
Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the...
Moderate
Unreviewed
CVE-2025-71422
was published
Sep 27, 2026
IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client...
Moderate
Unreviewed
CVE-2026-97732
was published
Sep 25, 2026
A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of...
Moderate
Unreviewed
CVE-2026-91814
was published
Sep 23, 2026
A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and...
Moderate
Unreviewed
CVE-2026-95503
was published
Sep 22, 2026
The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper...
Moderate
Unreviewed
CVE-2026-9832
was published
Sep 19, 2026
An authenticated user with access to the NetBackup Flex OS management
shell could read arbitrary...
Moderate
Unreviewed
CVE-2026-28199
was published
Sep 18, 2026
live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection...
Moderate
Unreviewed
CVE-2026-89169
was published
Sep 11, 2026
n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
Moderate
CVE-2026-86080
was published
for
n8n
(npm)
Sep 10, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
Moderate
Unreviewed
CVE-2026-79970
was published
Sep 9, 2026
An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM...
Moderate
Unreviewed
CVE-2026-87732
was published
Sep 9, 2026
An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify...
Moderate
Unreviewed
CVE-2026-52486
was published
Sep 8, 2026
MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because...
Moderate
Unreviewed
CVE-2026-67278
was published
Sep 5, 2026
AIIR verification and policy gates could report success without enforcing the control (fail-open)
Moderate
GHSA-73p9-6hrp-8qhr
was published
for
aiir
(pip)
Aug 28, 2026
The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an...
Moderate
Unreviewed
CVE-2026-72861
was published
Aug 20, 2026
The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of...
Moderate
Unreviewed
CVE-2026-50720
was published
Aug 19, 2026
A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an...
Moderate
Unreviewed
CVE-2026-74244
was published
Aug 15, 2026
Improper verification of cryptographic signature in Windows Schannel allows an unauthorized...
Moderate
Unreviewed
CVE-2026-62757
was published
Aug 11, 2026
SAP Approuter does not consistently enforce integrity verification on certain session-related...
Moderate
Unreviewed
CVE-2026-66776
was published
Aug 11, 2026
Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional...
Moderate
Unreviewed
CVE-2026-59112
was published
Aug 10, 2026
Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a...
Moderate
Unreviewed
CVE-2026-17872
was published
Jul 30, 2026
Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature...
Moderate
Unreviewed
CVE-2026-13305
was published
Jul 29, 2026
A TOTP two-factor authentication bypass vulnerability in
Koollab LMS allowed an
attacker to...
Moderate
Unreviewed
CVE-2026-63237
was published
Jul 29, 2026
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to...
Moderate
Unreviewed
CVE-2026-10723
was published
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API