GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,606
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,831
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
139 advisories
Filter by severity
fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)
Moderate
CVE-2026-35040
was published
for
fast-jwt
(npm)
Apr 9, 2026
Parse Server has a session field immutability bypass via falsy-value guard
Moderate
CVE-2026-34574
was published
for
parse-server
(npm)
Apr 1, 2026
mppx has Stripe charge credential replay via missing idempotency check
Moderate
CVE-2026-34210
was published
for
mppx
(npm)
Mar 29, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
Moderate
CVE-2026-32322
was published
for
soroban-sdk
(Rust)
Mar 13, 2026
PickleScan's profile.run blocklist mismatch allows exec() bypass
Critical
GHSA-7wx9-6375-f5wh
was published
for
picklescan
(pip)
Mar 3, 2026
Improper Digest Verification in httpsig-hyper May Allow Message Integrity Bypass
High
CVE-2026-26275
was published
for
httpsig-hyper
(Rust)
Feb 17, 2026
Bug fixes in hpke-rs, hpke-rs-rust-crypto
High
GHSA-g433-pq76-6cmf
was published
for
hpke-rs
(Rust)
Feb 13, 2026
A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures...
High
Unreviewed
CVE-2025-20343
was published
Nov 5, 2025
The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up...
Moderate
Unreviewed
CVE-2025-12192
was published
Nov 5, 2025
MantisBT vulnerable to authentication bypass for some passwords due to PHP type juggling
High
CVE-2025-47776
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
Dragonfly vulnerable to timing attacks against Proxy’s basic authentication
Moderate
CVE-2025-59350
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by...
Moderate
Unreviewed
CVE-2025-47416
was published
Sep 9, 2025
A vulnerability has been found in HuangDou UTCMS 9. This vulnerability affects unknown code of...
Moderate
Unreviewed
CVE-2025-9401
was published
Aug 25, 2025
In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct...
Critical
Unreviewed
CVE-2025-54336
was published
Aug 19, 2025
IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could...
Moderate
Unreviewed
CVE-2025-27909
was published
Aug 18, 2025
The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an...
High
Unreviewed
CVE-2025-3102
was published
Apr 10, 2025
An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17...
Low
Unreviewed
CVE-2024-5528
was published
Feb 5, 2025
TCPDF has incorrect comparison
High
CVE-2024-56522
was published
for
tecnickcom/tcpdf
(Composer)
Dec 27, 2024
`idna` accepts Punycode labels that do not produce any non-ASCII when decoded
Moderate
CVE-2024-12224
was published
for
idna
(Rust)
Dec 9, 2024
PyJWT Issuer field partial matches allowed
Low
CVE-2024-53861
was published
for
PyJWT
(pip)
Dec 2, 2024
When curl is asked to use HSTS, the expiry time for a subdomain might
overwrite a parent domain's...
Moderate
Unreviewed
CVE-2024-9681
was published
Nov 6, 2024
An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks...
Moderate
Unreviewed
CVE-2024-39534
was published
Oct 11, 2024
The WP Hardening – Fix Your WordPress Security plugin for WordPress is vulnerable to Security...
Moderate
Unreviewed
CVE-2024-6641
was published
Sep 18, 2024
Alpine allows Authentication Filter bypass
Moderate
CVE-2022-23554
was published
for
us.springett:alpine
(Maven)
Aug 5, 2024
Under certain circumstances the ExacqVision Web Services does not provide sufficient protection...
Moderate
Unreviewed
CVE-2024-32862
was published
Aug 2, 2024
ProTip!
Advisories are also available from the
GraphQL API