GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,549
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,798
Pub
13
RubyGems
1,038
Rust
1,237
Swift
53
Unreviewed advisories
All unreviewed
5,000+
139 advisories
Filter by severity
SP1 V6 Recursion Circuit Row-Count Binding Gap
High
CVE-2026-40323
was published
for
sp1_prover
(Rust)
Apr 14, 2026
In wolfSSL's EVP layer, the ChaCha20-Poly1305 AEAD decryption path in wolfSSL_EVP_CipherFinal ...
High
Unreviewed
CVE-2026-5479
was published
Apr 10, 2026
A padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to recover...
Moderate
Unreviewed
CVE-2026-5504
was published
Apr 10, 2026
SzafirHost downloads necessary files in the context of the initiating web page. When called,...
High
Unreviewed
CVE-2026-26928
was published
Apr 2, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
Critical
CVE-2026-33026
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 30, 2026
Incus does not verify combined fingerprint when downloading images from simplestreams servers
High
CVE-2026-33542
was published
for
github.com/lxc/incus/v6/client
(Go)
Mar 27, 2026
Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
High
CVE-2026-28498
was published
for
authlib
(pip)
Mar 16, 2026
simplesamlphp/xml-security: Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
High
CVE-2026-32600
was published
for
simplesamlphp/xml-security
(Composer)
Mar 13, 2026
xmlseclibs: Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
High
CVE-2026-32313
was published
for
robrichards/xmlseclibs
(Composer)
Mar 13, 2026
Striae has a hash validation utility vulnerability
High
CVE-2026-31839
was published
for
@striae-org/striae
(npm)
Mar 11, 2026
Improper Digest Verification in httpsig-hyper May Allow Message Integrity Bypass
High
CVE-2026-26275
was published
for
httpsig-hyper
(Rust)
Feb 17, 2026
rPGP's integrity protection of encrypted data was not always checked
Moderate
GHSA-c7ph-f7jm-xv4w
was published
for
pgp
(Rust)
Feb 13, 2026
go-git improperly verifies data integrity values for .idx and .pack files
Moderate
CVE-2026-25934
was published
for
github.com/go-git/go-git/v5
(Go)
Feb 10, 2026
Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors...
Critical
Unreviewed
CVE-2025-11543
was published
Dec 22, 2025
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause...
Moderate
Unreviewed
CVE-2025-33193
was published
Nov 25, 2025
An insufficient validation of an untrusted input vulnerability in Palo Alto Networks Prisma®...
Low
Unreviewed
CVE-2025-4616
was published
Nov 14, 2025
Protobuf Maven Plugin protocDigest is ignored when using protoc from PATH
Low
GHSA-j2pc-v64r-mv4f
was published
for
io.github.ascopes:protobuf-maven-plugin
(Maven)
Nov 4, 2025
Netskope has identified a potential gap in its agent (Netskope Client) in which a malicious...
High
Unreviewed
CVE-2024-7402
was published
Aug 14, 2025
JWE is missing AES-GCM authentication tag validation in encrypted JWE
Critical
CVE-2025-54887
was published
for
jwe
(RubyGems)
Aug 7, 2025
A vulnerability classified as critical was found in Comodo Internet Security Premium 12.3.4.8162....
High
Unreviewed
CVE-2025-7096
was published
Jul 7, 2025
electron ASAR Integrity bypass by just modifying the content
High
CVE-2024-46992
was published
for
electron
(npm)
Jun 30, 2025
A vulnerability exists in the IEC 61850 of the MicroSCADA X SYS600 product. An IEC 61850-8...
High
Unreviewed
CVE-2025-39203
was published
Jun 24, 2025
An improper validation of integrity check value vulnerability exists in
AVEVA PI Connector for...
Moderate
Unreviewed
CVE-2025-4418
was published
Jun 12, 2025
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-3479
was published
Apr 17, 2025
The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and...
Moderate
Unreviewed
CVE-2025-3247
was published
Apr 16, 2025
ProTip!
Advisories are also available from the
GraphQL API