GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
151 advisories
Filter by severity
Incorrect comparison for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3:...
Moderate
Unreviewed
CVE-2026-20765
was published
Aug 11, 2026
Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in...
High
Unreviewed
CVE-2026-67207
was published
Jul 30, 2026
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
High
CVE-2026-55771
was published
for
com.cedarpolicy:cedar-java
(Maven)
Jul 28, 2026
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
Moderate
CVE-2026-59890
was published
for
setuptools
(pip)
Jul 21, 2026
A vulnerability was found in HdrHistogram up to 2.2.2. This issue affects the function org...
Low
Unreviewed
CVE-2026-14686
was published
Jul 5, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host
High
CVE-2026-49340
was published
for
go.senan.xyz/gonic
(Go)
Jun 26, 2026
js-toml has silent type confusion via falsy-primitive duplicate-key bypass
Moderate
CVE-2026-50029
was published
for
js-toml
(npm)
Jun 26, 2026
ML-KEM-1024 x64 AVX2 implicit rejection failure in the Fujisaki-Okamoto transform breaks IND-CCA2...
Moderate
Unreviewed
CVE-2026-10097
was published
Jun 25, 2026
@hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers
High
CVE-2026-48032
was published
for
@hulumi/policies
(npm)
Jun 10, 2026
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
High
CVE-2026-44249
was published
for
io.netty:netty-handler
(Maven)
Jun 8, 2026
hermes-agent has an Incorrect Comparison
Low
CVE-2026-9369
was published
for
hermes-agent
(pip)
May 26, 2026
fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)
Moderate
CVE-2026-35040
was published
for
fast-jwt
(npm)
Apr 9, 2026
Parse Server has a session field immutability bypass via falsy-value guard
Moderate
CVE-2026-34574
was published
for
parse-server
(npm)
Apr 1, 2026
mppx has Stripe charge credential replay via missing idempotency check
Moderate
CVE-2026-34210
was published
for
mppx
(npm)
Mar 29, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
Moderate
CVE-2026-32322
was published
for
soroban-sdk
(Rust)
Mar 13, 2026
PickleScan's profile.run blocklist mismatch allows exec() bypass
Critical
CVE-2026-53873
was published
for
picklescan
(pip)
Mar 3, 2026
Improper Digest Verification in httpsig-hyper May Allow Message Integrity Bypass
High
CVE-2026-26275
was published
for
httpsig-hyper
(Rust)
Feb 17, 2026
Bug fixes in hpke-rs, hpke-rs-rust-crypto
High
GHSA-g433-pq76-6cmf
was published
for
hpke-rs
(Rust)
Feb 13, 2026
A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures...
High
Unreviewed
CVE-2025-20343
was published
Nov 5, 2025
The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up...
Moderate
Unreviewed
CVE-2025-12192
was published
Nov 5, 2025
MantisBT vulnerable to authentication bypass for some passwords due to PHP type juggling
High
CVE-2025-47776
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
Dragonfly vulnerable to timing attacks against Proxy’s basic authentication
Moderate
CVE-2025-59350
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by...
Moderate
Unreviewed
CVE-2025-47416
was published
Sep 9, 2025
A vulnerability has been found in HuangDou UTCMS 9. This vulnerability affects unknown code of...
Moderate
Unreviewed
CVE-2025-9401
was published
Aug 25, 2025
In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct...
Critical
Unreviewed
CVE-2025-54336
was published
Aug 19, 2025
ProTip!
Advisories are also available from the
GraphQL API