GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,912
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
114 advisories
Filter by severity
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another...
Low
Unreviewed
CVE-2026-46582
was published
Jul 22, 2026
Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum...
Moderate
Unreviewed
CVE-2026-65058
was published
Jul 21, 2026
Improperly implemented security check for standard in Windows Secure Boot allows an authorized...
High
Unreviewed
CVE-2026-49783
was published
Jul 14, 2026
In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web...
Moderate
Unreviewed
CVE-2026-54431
was published
Jul 2, 2026
DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability.
High
Unreviewed
CVE-2026-12577
was published
Jul 1, 2026
Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
Critical
CVE-2026-48797
was published
for
@mcptoolshop/backpropagate
(npm)
Jun 26, 2026
It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA...
High
Unreviewed
CVE-2026-57915
was published
Jun 26, 2026
Apache CXF OAuth2 has Inverted IP Binding Check that Defeats Security Control
Critical
CVE-2026-50628
was published
for
org.apache.cxf:cxf-rt-rs-security-oauth2
(Maven)
Jun 12, 2026
Inappropriate implementation in WebAPKs in Google Chrome on Android prior to 149.0.7827.53...
Moderate
Unreviewed
CVE-2026-11127
was published
Jun 5, 2026
Inappropriate implementation in Keyboard in Google Chrome prior to 149.0.7827.53 allowed a remote...
Moderate
Unreviewed
CVE-2026-11122
was published
Jun 5, 2026
A logic issue was addressed with improved file handling. This issue is fixed in macOS Tahoe 26.5....
Moderate
Unreviewed
CVE-2026-28914
was published
May 11, 2026
MantisBT has a Content Security Policy bypass via attachments
High
CVE-2026-40597
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
Ella Core has handover failures during concurrent Security Mode Command
Low
CVE-2026-44474
was published
for
github.com/ellanetworks/core
(Go)
May 11, 2026
Ella Core has a UE Security Capability bypass on NGAP PathSwitchRequest
Moderate
CVE-2026-44475
was published
for
github.com/ellanetworks/core
(Go)
May 11, 2026
Ella Core Vulnerable to UE Downlink Redirection via Forged PDUSessionResourceSetupResponse
High
CVE-2026-44473
was published
for
github.com/ellanetworks/core
(Go)
May 11, 2026
Free5GC AMF has Missing Concurrent NAS SMC Validation During NGAP Handover
Low
CVE-2026-42082
was published
for
github.com/free5gc/amf
(Go)
May 7, 2026
Free5GC AMF Bypasses UE Security Capabilities on NGAP PathSwitchRequest
Moderate
CVE-2026-42081
was published
for
github.com/free5gc/amf
(Go)
May 7, 2026
HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due...
Low
Unreviewed
CVE-2025-31983
was published
May 6, 2026
HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the...
Moderate
Unreviewed
CVE-2025-31970
was published
May 6, 2026
A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an...
Moderate
Unreviewed
CVE-2026-22618
was published
Apr 16, 2026
Inappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allowed a remote...
Moderate
Unreviewed
CVE-2026-5894
was published
Apr 9, 2026
Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions,...
Low
Unreviewed
CVE-2026-35679
was published
Apr 6, 2026
In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine...
Moderate
Unreviewed
CVE-2026-2645
was published
Mar 19, 2026
Missing Authorization vulnerability in hcaptcha hCaptcha for WP hcaptcha-for-forms-and-more...
Moderate
Unreviewed
CVE-2026-25315
was published
Feb 19, 2026
IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during...
Moderate
Unreviewed
CVE-2025-13333
was published
Feb 18, 2026
ProTip!
Advisories are also available from the
GraphQL API