GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
3,725 advisories
Filter by severity
A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of...
Moderate
Unreviewed
CVE-2026-19379
was published
Aug 10, 2026
A security vulnerability has been detected in HKUDS nanobot up to 0.2.1. Impacted is the function...
Low
Unreviewed
CVE-2026-19243
was published
Aug 7, 2026
A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function...
High
Unreviewed
CVE-2026-19036
was published
Aug 6, 2026
A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function...
High
Unreviewed
CVE-2026-19035
was published
Aug 6, 2026
A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the...
High
Unreviewed
CVE-2026-19034
was published
Aug 6, 2026
The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions...
High
Unreviewed
CVE-2026-7693
was published
Aug 5, 2026
A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the...
High
Unreviewed
CVE-2026-18900
was published
Aug 5, 2026
H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010...
Critical
Unreviewed
CVE-2025-29296
was published
Aug 4, 2026
A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up...
Moderate
Unreviewed
CVE-2026-18641
was published
Aug 3, 2026
A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown...
Moderate
Unreviewed
CVE-2026-18587
was published
Aug 3, 2026
A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function...
Low
Unreviewed
CVE-2026-18590
was published
Aug 3, 2026
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments...
High
Unreviewed
CVE-2026-67323
was published
Aug 1, 2026
TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerability in...
High
Unreviewed
CVE-2026-38710
was published
Jul 31, 2026
TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10,...
Critical
Unreviewed
CVE-2026-38708
was published
Jul 31, 2026
TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10,...
Critical
Unreviewed
CVE-2026-38713
was published
Jul 31, 2026
TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10,...
Critical
Unreviewed
CVE-2026-38711
was published
Jul 31, 2026
Successful exploitation of the
command injection vulnerability could allow an attacker to execute...
High
Unreviewed
CVE-2026-43830
was published
Jul 31, 2026
TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10,...
Critical
Unreviewed
CVE-2026-38709
was published
Jul 31, 2026
An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the...
Critical
Unreviewed
CVE-2026-35847
was published
Jul 30, 2026
Due to improper neutralization of special elements, an unauthenticated remote attacker is able to...
Critical
Unreviewed
CVE-2026-7849
was published
Jul 30, 2026
Logging operator has Fluentd configuration injection that allows remote code execution
Critical
CVE-2026-54680
was published
for
github.com/kube-logging/logging-operator
(Go)
Jul 29, 2026
cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover...
High
Unreviewed
CVE-2024-58354
was published
Jul 24, 2026
A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected...
Low
Unreviewed
CVE-2026-16763
was published
Jul 24, 2026
A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element...
Low
Unreviewed
CVE-2026-16733
was published
Jul 23, 2026
A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1....
Low
Unreviewed
CVE-2026-16735
was published
Jul 23, 2026
ProTip!
Advisories are also available from the
GraphQL API