GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,683
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,535
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
13,137 advisories
Filter by severity
Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver...
Moderate
Unreviewed
CVE-2026-85528
was published
Sep 4, 2026
Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977...
Critical
Unreviewed
CVE-2026-85047
was published
Sep 3, 2026
A vulnerability in MISP's event template handling allowed an authenticated user with permission...
High
Unreviewed
CVE-2026-85239
was published
Sep 3, 2026
Insufficient input validation in ABR allows a low-privileged user to inject malicious entries...
High
Unreviewed
CVE-2026-78237
was published
Sep 3, 2026
A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget...
Moderate
Unreviewed
CVE-2026-85230
was published
Sep 3, 2026
n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo...
High
Unreviewed
CVE-2026-85170
was published
Sep 3, 2026
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
High
CVE-2026-75975
was published
for
fast-uri
(npm)
Sep 2, 2026
Vulnerability in Drupal Link content parser. This issue affects Link content parser versions: *.*.
Moderate
Unreviewed
CVE-2026-76758
was published
Sep 2, 2026
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
Moderate
CVE-2026-18504
was published
for
fastify
(npm)
Sep 2, 2026
CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)
Moderate
CVE-2026-73845
was published
for
@aborruso/ckan-mcp-server
(npm)
Sep 2, 2026
Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote...
Moderate
Unreviewed
CVE-2026-84357
was published
Sep 2, 2026
Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a...
Critical
Unreviewed
CVE-2026-84325
was published
Sep 2, 2026
A vulnerability exists in the command line interface of AOS-CX that may allow for improper...
High
Unreviewed
CVE-2026-73768
was published
Sep 1, 2026
Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.
Critical
Unreviewed
CVE-2026-84135
was published
Sep 1, 2026
Socket.IO: Engine.IO WebTransport SID DoS
High
CVE-2026-59724
was published
for
engine.io
(npm)
Aug 31, 2026
Improper input validation vulnerability in Extend Themes Kubio AI Website Builder.
This issue...
Moderate
Unreviewed
CVE-2026-83492
was published
Aug 31, 2026
A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown...
Moderate
Unreviewed
CVE-2026-82550
was published
Aug 30, 2026
WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the...
High
Unreviewed
CVE-2026-82648
was published
Aug 30, 2026
NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in...
High
Unreviewed
CVE-2026-82639
was published
Aug 30, 2026
A malicious actor with access to the network could exploit an Improper Input Validation...
Critical
Unreviewed
CVE-2026-77554
was published
Aug 28, 2026
A malicious actor with access to the network and low privileges could exploit an Improper Input...
Critical
Unreviewed
CVE-2026-77546
was published
Aug 28, 2026
A malicious actor with access to the network and low privileges could exploit an Improper Input...
Critical
Unreviewed
CVE-2026-77543
was published
Aug 28, 2026
A malicious actor with access to the network and low privileges could exploit an Improper Input...
Critical
Unreviewed
CVE-2026-77547
was published
Aug 28, 2026
A malicious actor with access to the network and low privileges could exploit an Improper Input...
Critical
Unreviewed
CVE-2026-77548
was published
Aug 28, 2026
A malicious actor with access to the network could exploit an Improper Input Validation...
Critical
Unreviewed
CVE-2026-77537
was published
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API