GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
316,983 advisories
Filter by severity
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially...
Moderate
Unreviewed
CVE-2026-63144
was published
Jul 22, 2026
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information...
Moderate
Unreviewed
CVE-2026-63259
was published
Jul 22, 2026
A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the...
Low
Unreviewed
CVE-2026-16488
was published
Jul 22, 2026
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected...
Low
Unreviewed
CVE-2026-16485
was published
Jul 22, 2026
A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the...
Low
Unreviewed
CVE-2026-16517
was published
Jul 22, 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via...
Moderate
Unreviewed
CVE-2026-63263
was published
Jul 22, 2026
Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who...
Unknown
Unreviewed
CVE-2026-16423
was published
Jul 22, 2026
Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a...
Unknown
Unreviewed
CVE-2026-16421
was published
Jul 22, 2026
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects...
Low
Unreviewed
CVE-2026-16486
was published
Jul 22, 2026
Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to...
Unknown
Unreviewed
CVE-2026-16420
was published
Jul 22, 2026
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive...
Moderate
Unreviewed
CVE-2026-63260
was published
Jul 22, 2026
A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function...
Low
Unreviewed
CVE-2026-16489
was published
Jul 22, 2026
Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote...
Unknown
Unreviewed
CVE-2026-16424
was published
Jul 22, 2026
Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning...
Moderate
Unreviewed
CVE-2026-63145
was published
Jul 22, 2026
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive...
Moderate
Unreviewed
CVE-2026-63261
was published
Jul 22, 2026
Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150...
Unknown
Unreviewed
CVE-2026-16422
was published
Jul 22, 2026
Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information...
Moderate
Unreviewed
CVE-2026-63262
was published
Jul 22, 2026
Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with...
Moderate
Unreviewed
CVE-2026-63142
was published
Jul 22, 2026
Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed...
Unknown
Unreviewed
CVE-2026-16419
was published
Jul 22, 2026
Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via...
Moderate
Unreviewed
CVE-2026-63143
was published
Jul 22, 2026
Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to...
Unknown
Unreviewed
CVE-2026-16418
was published
Jul 22, 2026
Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery...
Critical
Unreviewed
CVE-2026-65318
was published
Jul 22, 2026
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the ...
Critical
Unreviewed
CVE-2026-8985
was published
Jul 22, 2026
Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined...
Critical
Unreviewed
CVE-2026-65317
was published
Jul 22, 2026
Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that...
High
Unreviewed
CVE-2026-8988
was published
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API