GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,169
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
264 advisories
Filter by severity
CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
Moderate
CVE-2026-54775
was published
for
CoreWCF.Kafka
(NuGet)
Jun 19, 2026
protobufjs : Schema-derived names can shadow runtime-significant properties
Moderate
CVE-2026-54269
was published
for
protobufjs
(npm)
Jun 15, 2026
A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN...
Moderate
Unreviewed
CVE-2026-0269
was published
Jun 11, 2026
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14...
Moderate
Unreviewed
CVE-2026-4915
was published
May 26, 2026
Improper Check for Unusual or Exceptional Conditions vulnerability in Samsung Open Source...
Moderate
Unreviewed
CVE-2026-47315
was published
May 19, 2026
Mattermost doesn't validate the response body of proxied images
Moderate
CVE-2026-4054
was published
for
github.com/mattermost/mattermost-server
(Go)
May 15, 2026
A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally...
Moderate
Unreviewed
CVE-2026-0235
was published
May 13, 2026
Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass...
Moderate
Unreviewed
CVE-2026-0241
was published
May 13, 2026
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an...
Moderate
Unreviewed
CVE-2026-0262
was published
May 13, 2026
ELECOM wireless LAN access point devices do not check if language parameter has an appropriate...
Moderate
Unreviewed
CVE-2026-42950
was published
May 13, 2026
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device...
Moderate
Unreviewed
CVE-2026-20754
was published
May 12, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request)
Moderate
CVE-2026-44324
was published
for
github.com/free5gc/udr
(Go)
May 8, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference
Moderate
CVE-2026-44317
was published
for
github.com/free5gc/pcf
(Go)
May 8, 2026
Admidio Missing Minimum Administrator Check in Role Membership Removal
Moderate
CVE-2026-41662
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
nimiq-blockchain: Peer-triggerable panic during history sync
Moderate
CVE-2026-34066
was published
for
nimiq-blockchain
(Rust)
Apr 22, 2026
uutils coreutils has an Improper Check for Unusual or Exceptional Conditions
Moderate
CVE-2026-35366
was published
for
coreutils
(Rust)
Apr 22, 2026
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation
Moderate
CVE-2026-40343
was published
for
github.com/free5gc/udr
(Go)
Apr 21, 2026
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or...
Moderate
Unreviewed
CVE-2025-43883
was published
Apr 16, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors
Moderate
CVE-2026-40249
was published
for
github.com/free5gc/udr
(Go)
Apr 14, 2026
Improper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows...
Moderate
Unreviewed
CVE-2026-21007
was published
Apr 13, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control...
Moderate
Unreviewed
CVE-2026-33787
was published
Apr 10, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control...
Moderate
Unreviewed
CVE-2026-33786
was published
Apr 10, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding...
Moderate
Unreviewed
CVE-2026-33774
was published
Apr 10, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails
Moderate
CVE-2026-39395
was published
for
github.com/sigstore/cosign
(Go)
Apr 8, 2026
Mattermost: Authenticated DoS through failure to prevent rendering of external SVGs on link embeds
Moderate
CVE-2026-20719
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 25, 2026
ProTip!
Advisories are also available from the
GraphQL API