GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,857
Maven
5,000+
npm
4,488
NuGet
780
pip
4,243
Pub
12
RubyGems
975
Rust
1,095
Swift
49
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
11,335 advisories
Filter by severity
Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10,...
Low
Unreviewed
CVE-2026-22281
was published
Jan 22, 2026
Improper authentication and missing CSRF protection in the local setup interface component in HCL...
Low
Unreviewed
CVE-2025-31963
was published
Jan 7, 2026
Neo4j Enterprise edition versions prior to 2025.11.2 and 5.26.17 are vulnerable to a potential...
Low
Unreviewed
CVE-2025-12738
was published
Jan 22, 2026
A vulnerability has been identified in the libarchive library, specifically within the...
Low
Unreviewed
CVE-2025-5914
was published
Jun 9, 2025
HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in...
Low
Unreviewed
CVE-2026-21640
was published
Jan 20, 2026
A flaw in Node.js's permission model allows a file's access and modification timestamps to be...
Low
Unreviewed
CVE-2025-55132
was published
Jan 20, 2026
Vulnerability in Oracle Java SE (component: JavaFX). Supported versions that are affected are...
Low
Unreviewed
CVE-2026-21947
was published
Jan 21, 2026
RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow...
Low
Unreviewed
CVE-2026-22213
was published
Jan 13, 2026
A flaw was found in glib. Missing validation of offset and count parameters in the...
Low
Unreviewed
CVE-2026-0988
was published
Jan 21, 2026
Vulnerability in the Oracle Zero Data Loss Recovery Appliance Software product of Oracle Zero...
Low
Unreviewed
CVE-2026-21977
was published
Jan 21, 2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). ...
Low
Unreviewed
CVE-2026-21965
was published
Jan 21, 2026
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component:...
Low
Unreviewed
CVE-2026-21930
was published
Jan 21, 2026
IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to...
Low
Unreviewed
CVE-2025-36411
was published
Jan 20, 2026
IBM ApplinX 11.1 could allow an authenticated user to perform unauthorized administrative actions...
Low
Unreviewed
CVE-2025-36410
was published
Jan 20, 2026
Missing Authorization vulnerability in WC Lovers WCFM – Frontend Manager for WooCommerce wc...
Low
Unreviewed
CVE-2025-54004
was published
Dec 16, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in shinetheme Traveler Option...
Low
Unreviewed
CVE-2025-49300
was published
Dec 16, 2025
Missing Authorization vulnerability in Automattic Crowdsignal Forms crowdsignal-forms allows...
Low
Unreviewed
CVE-2025-69015
was published
Dec 30, 2025
Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential...
Low
Unreviewed
CVE-2025-64352
was published
Oct 31, 2025
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Frank Goossens WP YouTube...
Low
Unreviewed
CVE-2025-66062
was published
Nov 21, 2025
Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows...
Low
Unreviewed
CVE-2025-64350
was published
Oct 31, 2025
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function...
Low
Unreviewed
CVE-2026-1196
was published
Jan 20, 2026
A vulnerability was detected in MineAdmin 1.x/2.x. Affected by this vulnerability is an unknown...
Low
Unreviewed
CVE-2026-1197
was published
Jan 20, 2026
HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use...
Low
Unreviewed
CVE-2025-55252
was published
Jan 19, 2026
HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose...
Low
Unreviewed
CVE-2025-55250
was published
Jan 19, 2026
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file...
Low
Unreviewed
CVE-2025-52660
was published
Jan 19, 2026
ProTip!
Advisories are also available from the
GraphQL API