GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,175
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
44 advisories
Filter by severity
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View...
Low
Unreviewed
CVE-2026-8491
was published
May 20, 2026
Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from...
Low
Unreviewed
CVE-2026-4643
was published
May 18, 2026
OpenClaw: Security Scan Failure Does Not Block Plugin Installation (Fail-Open)
Low
CVE-2026-41377
was published
for
openclaw
(npm)
Apr 2, 2026
Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which...
Low
Unreviewed
CVE-2026-3109
was published
Mar 26, 2026
@grackle-ai/server JSON.parse lacks try-catch logic in its gRPC Service AdapterConfig Handling
Low
GHSA-8g29-8xwr-qmhr
was published
for
@grackle-ai/server
(npm)
Mar 25, 2026
Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Improper Check for...
Low
Unreviewed
CVE-2026-22760
was published
Mar 4, 2026
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User...
Low
Unreviewed
CVE-2025-33030
was published
Feb 10, 2026
Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS...
Low
Unreviewed
CVE-2025-32739
was published
Feb 10, 2026
ingress-nginx has Improper Check for Unusual or Exceptional Conditions
Low
CVE-2026-24513
was published
for
k8s.io/ingress-nginx
(Go)
Feb 4, 2026
Drupal core allows Forceful Browsing
Low
CVE-2025-13080
was published
for
drupal/core
(Composer)
Nov 18, 2025
In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web...
Low
Unreviewed
CVE-2025-52136
was published
Aug 10, 2025
Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore...
Low
Unreviewed
CVE-2024-12533
was published
May 13, 2025
XMP Toolkit's `XmpFile::close` can trigger undefined behavior
Low
GHSA-66fw-43h8-f8p3
was published
for
xmp_toolkit
(Rust)
Jul 26, 2024
7-Zip through 24.09 does not report an error for certain invalid xz files, involving stream flags...
Low
Unreviewed
CVE-2022-47112
was published
Apr 19, 2025
7-Zip through 24.09 does not report an error for certain invalid xz files, involving block flags...
Low
Unreviewed
CVE-2022-47111
was published
Apr 19, 2025
In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data...
Low
Unreviewed
CVE-2025-30258
was published
Mar 19, 2025
Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint...
Low
Unreviewed
CVE-2025-0503
was published
Feb 14, 2025
Mattermost has Improper Check for Unusual or Exceptional Conditions
Low
CVE-2025-22445
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 9, 2025
CHECK-fail in `QuantizeAndDequantizeV4Grad`
Low
CVE-2021-29544
was published
for
tensorflow
(pip)
May 21, 2021
Moodle has insufficient capability checks
Low
CVE-2024-43435
was published
for
moodle/moodle
(Composer)
Nov 11, 2024
In ShortcutInfo of ShortcutInfo.java, there is a possible way for an app to retain notification...
Low
Unreviewed
CVE-2023-21246
was published
Jul 13, 2023
CHECK-fail in tf.raw_ops.EncodePng
Low
CVE-2021-29531
was published
for
tensorflow
(pip)
May 21, 2021
Segmentation faultin TensorFlow when converting a Python string to `tf.float16`
Low
CVE-2020-5215
was published
for
tensorflow
(pip)
Jan 28, 2020
ProTip!
Advisories are also available from the
GraphQL API