GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
23 advisories
Filter by severity
For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data...
Moderate
Unreviewed
CVE-2026-19033
was published
Sep 16, 2026
A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone...
Moderate
Unreviewed
CVE-2026-78301
was published
Sep 16, 2026
The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related...
Moderate
Unreviewed
CVE-2026-74916
was published
Sep 1, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2...
Moderate
Unreviewed
CVE-2026-15387
was published
Aug 26, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
Moderate
CVE-2026-54625
was published
for
django-cms
(pip)
Aug 24, 2026
In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and...
Moderate
Unreviewed
CVE-2026-50252
was published
Jul 22, 2026
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous...
Moderate
Unreviewed
CVE-2026-42960
was published
May 20, 2026
OpenClaw: Zalo replay dedupe keys could suppress messages across chats or senders
Moderate
CVE-2026-41354
was published
for
openclaw
(npm)
Apr 7, 2026
In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote...
Moderate
Unreviewed
CVE-2025-68269
was published
Dec 16, 2025
NLnet Labs Unbound up to and including version 1.24.0 is vulnerable to possible domain hijack...
Moderate
Unreviewed
CVE-2025-11411
was published
Oct 22, 2025
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in...
Moderate
Unreviewed
CVE-2025-11703
was published
Oct 18, 2025
Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an...
Moderate
Unreviewed
CVE-2025-48804
was published
Jul 8, 2025
A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated,...
Moderate
Unreviewed
CVE-2025-20255
was published
May 21, 2025
check-jsonschema default caching for remote schemas allows for cache confusion
Moderate
CVE-2024-53848
was published
for
check-jsonschema
(pip)
Dec 2, 2024
In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via...
Moderate
Unreviewed
CVE-2024-52555
was published
Nov 15, 2024
The pagination class includes arbitrary parameters in links, leading to cache poisoning attack...
Moderate
Unreviewed
CVE-2024-27185
was published
Aug 20, 2024
aiosmtpd STARTTLS unencrypted commands injection
Moderate
CVE-2024-34083
was published
for
aiosmtpd
(pip)
May 20, 2024
Argument injection in websphere_mq agent plugin in Checkmk 2.0.0, 2.1.0, <2.2.0p25 and <2.3.0b5...
Moderate
Unreviewed
CVE-2024-3367
was published
Apr 16, 2024
In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode...
Moderate
Unreviewed
CVE-2023-51655
was published
Dec 21, 2023
Moodle Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability
Moderate
CVE-2023-5548
was published
for
moodle/moodle
(Composer)
Nov 9, 2023
AsyncSSH Rogue Extension Negotiation
Moderate
CVE-2023-46445
was published
for
asyncssh
(pip)
Nov 9, 2023
A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.
Moderate
Unreviewed
CVE-2023-3749
was published
Aug 3, 2023
Symfony HTTP Foundation web cache poisoning
Moderate
CVE-2018-14773
was published
for
symfony/http-foundation
(Composer)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API