GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,549
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,798
Pub
13
RubyGems
1,038
Rust
1,237
Swift
53
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
298,416 advisories
Filter by severity
Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize...
Low
Unreviewed
CVE-2026-0930
was published
Apr 21, 2026
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are...
Low
Unreviewed
CVE-2026-22051
was published
Apr 21, 2026
XiangShan (Open-source high-performance RISC-V processor) commit...
Unknown
Unreviewed
CVE-2026-29643
was published
Apr 21, 2026
The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for...
Moderate
Unreviewed
CVE-2026-5721
was published
Apr 21, 2026
HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability...
Moderate
Unreviewed
CVE-2026-6729
was published
Apr 21, 2026
In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a...
Moderate
Unreviewed
CVE-2026-41285
was published
Apr 21, 2026
Calling the ungetwc function on a FILE stream with wide characters encoded in a character set...
Unknown
Unreviewed
CVE-2026-5928
was published
Apr 20, 2026
The obsolete nis_local_principal function in the GNU C Library version 2.43 and older may...
Unknown
Unreviewed
CVE-2026-5358
was published
Apr 20, 2026
In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code...
Unknown
Unreviewed
CVE-2026-29647
was published
Apr 20, 2026
The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-4852
was published
Apr 20, 2026
Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library...
Unknown
Unreviewed
CVE-2026-5450
was published
Apr 20, 2026
In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly...
Unknown
Unreviewed
CVE-2026-29648
was published
Apr 20, 2026
Vvveb CMS 1.0.8 contains a remote code execution vulnerability in its media upload handler that...
High
Unreviewed
CVE-2026-6249
was published
Apr 20, 2026
In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a...
Unknown
Unreviewed
CVE-2026-29646
was published
Apr 20, 2026
A local attacker who can execute privileged CSR operations (or can induce firmware to do so)...
Unknown
Unreviewed
CVE-2026-29642
was published
Apr 20, 2026
The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all...
High
Unreviewed
CVE-2026-5478
was published
Apr 20, 2026
Vvveb CMS v1.0.8 contains a remote code execution vulnerability in its media management...
Critical
Unreviewed
CVE-2026-6257
was published
Apr 20, 2026
NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] ...
Unknown
Unreviewed
CVE-2026-29649
was published
Apr 20, 2026
Rejected reason: This CVE id was assigned as a duplicate of CVE-2025-66414.
Unknown
Unreviewed
CVE-2025-11249
was published
Apr 20, 2026
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to...
High
Unreviewed
CVE-2026-6248
was published
Apr 20, 2026
A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource...
Moderate
Unreviewed
CVE-2026-6060
was published
Apr 20, 2026
NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in...
Unknown
Unreviewed
CVE-2026-29645
was published
Apr 20, 2026
OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result...
Moderate
Unreviewed
CVE-2026-41389
was published
Apr 20, 2026
SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management...
High
Unreviewed
CVE-2026-39111
was published
Apr 20, 2026
Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors...
Moderate
Unreviewed
CVE-2026-39112
was published
Apr 20, 2026
ProTip!
Advisories are also available from the
GraphQL API