GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,863
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,586
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
4,513 advisories
Filter by severity
YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows...
High
Unreviewed
CVE-2026-104443
was published
Oct 2, 2026
RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object)...
High
Unreviewed
CVE-2026-82358
was published
Oct 1, 2026
SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
Moderate
CVE-2026-73606
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
Critical
CVE-2026-92951
was published
for
vm2
(npm)
Oct 1, 2026
vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
Moderate
CVE-2026-92945
was published
for
vm2
(npm)
Oct 1, 2026
SiYuan discloses an administrator's open documents and search terms to anonymous readers
Moderate
CVE-2026-72788
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows...
High
Unreviewed
CVE-2026-103758
was published
Oct 1, 2026
Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the...
Moderate
Unreviewed
CVE-2026-103284
was published
Oct 1, 2026
Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in...
Moderate
Unreviewed
CVE-2026-103265
was published
Oct 1, 2026
Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower...
Moderate
Unreviewed
CVE-2026-103273
was published
Oct 1, 2026
Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows...
High
Unreviewed
CVE-2026-103271
was published
Oct 1, 2026
Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, without...
High
Unreviewed
CVE-2026-103266
was published
Oct 1, 2026
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability...
High
Unreviewed
CVE-2026-103259
was published
Oct 1, 2026
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to...
High
Unreviewed
CVE-2026-103488
was published
Oct 1, 2026
Hitachi Coding Software Suite contains an Incorrect Authorization vulnerability that allows an...
High
Unreviewed
CVE-2026-82828
was published
Oct 1, 2026
In affected versions of Octopus Server, users with certain scoped permission sets could execute...
High
Unreviewed
CVE-2026-78210
was published
Oct 1, 2026
In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication...
Critical
Unreviewed
CVE-2026-103547
was published
Sep 30, 2026
OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the...
High
Unreviewed
CVE-2026-101880
was published
Sep 30, 2026
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an...
High
Unreviewed
CVE-2026-47591
was published
Sep 30, 2026
NVIDIA GPU Display Driver for Windows contains a vulnerability in kernel-mode escape handling...
High
Unreviewed
CVE-2026-47571
was published
Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility...
Moderate
Unreviewed
CVE-2026-100276
was published
Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide...
Moderate
Unreviewed
CVE-2026-100278
was published
Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a...
High
Unreviewed
CVE-2026-100277
was published
Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed...
High
Unreviewed
CVE-2026-100273
was published
Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose...
Low
Unreviewed
CVE-2026-100270
was published
Sep 30, 2026
ProTip!
Advisories are also available from the
GraphQL API