GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
132 advisories
Filter by severity
Craft CMS has a potential information disclosure vulnerability in preview tokens
Low
CVE-2026-29113
was published
for
craftcms/cms
(Composer)
Mar 10, 2026
A vulnerability has been found in Cleo Harmony up to 5.8.1.10. Impacted is the function...
Low
Unreviewed
CVE-2026-84114
was published
Sep 1, 2026
A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the...
Low
Unreviewed
CVE-2026-82906
was published
Aug 31, 2026
An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02...
Low
Unreviewed
CVE-2026-1524
was published
Mar 11, 2026
A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an...
Low
Unreviewed
CVE-2026-75774
was published
Aug 18, 2026
A security flaw has been discovered in treefrogframework treefrog-framework up to 2.11.2. This...
Low
Unreviewed
CVE-2026-19974
was published
Aug 17, 2026
A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C,...
Low
Unreviewed
CVE-2026-19749
was published
Aug 13, 2026
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
Low
CVE-2026-71326
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict...
Low
Unreviewed
CVE-2026-14214
was published
Aug 1, 2026
A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the...
Low
Unreviewed
CVE-2026-18816
was published
Aug 5, 2026
The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on...
Low
Unreviewed
CVE-2026-11366
was published
Aug 4, 2026
This issue was addressed with additional restrictions on the lock screen. This issue is fixed in...
Low
Unreviewed
CVE-2026-64745
was published
Jul 27, 2026
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Siebel...
Low
Unreviewed
CVE-2026-60357
was published
Jul 22, 2026
A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown...
Low
Unreviewed
CVE-2026-16198
was published
Jul 19, 2026
A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the...
Low
Unreviewed
CVE-2026-16076
was published
Jul 18, 2026
A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the...
Low
Unreviewed
CVE-2026-16015
was published
Jul 17, 2026
A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. This...
Low
Unreviewed
CVE-2026-14627
was published
Jul 4, 2026
A vulnerability was detected in Documenso up to 2.11.0. Affected by this vulnerability is an...
Low
Unreviewed
CVE-2026-13543
was published
Jun 29, 2026
lxd has a restricted TLS certificate privilege escalation when in PKI mode
Low
CVE-2024-6219
was published
for
github.com/canonical/lxd
(Go)
Dec 9, 2024
The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129....
Low
Unreviewed
CVE-2026-44961
was published
Jun 23, 2026
A person with access to a Mac may be able to bypass Login Window. A consistency issue was...
Low
Unreviewed
CVE-2022-48575
was published
Jun 11, 2026
A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects...
Low
Unreviewed
CVE-2026-10548
was published
Jun 2, 2026
A security vulnerability has been detected in ItzCrazyKns Vane up to 1.12.1. Affected by this...
Low
Unreviewed
CVE-2026-9371
was published
May 26, 2026
A security vulnerability has been detected in Besen BS20 EV Charging Station up to 20260426. This...
Low
Unreviewed
CVE-2026-9398
was published
May 26, 2026
Incus has an OVN TLS Verification that Accepts Peer-Supplied Roots
Low
CVE-2026-40243
was published
for
github.com/lxc/incus/v6/cmd/incusd
(Go)
May 4, 2026
ProTip!
Advisories are also available from the
GraphQL API