GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,582
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
13,096 advisories
Filter by severity
An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote...
High
Unreviewed
CVE-2026-78009
was published
Aug 28, 2026
Affected versions of Flowintel incorrectly attempted to validate login email addresses by calling...
Moderate
Unreviewed
CVE-2026-81827
was published
Aug 27, 2026
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents,...
Critical
Unreviewed
CVE-2026-81707
was published
Aug 27, 2026
openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org...
Moderate
Unreviewed
CVE-2026-81686
was published
Aug 27, 2026
silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template
High
CVE-2026-54718
was published
for
symbiote/silverstripe-advancedworkflow
(Composer)
Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
High
CVE-2026-54721
was published
for
silverstripe/userforms
(Composer)
Aug 27, 2026
Affected versions of Flowintel improperly trust configuration keys supplied to the alerts...
High
Unreviewed
CVE-2026-81662
was published
Aug 27, 2026
In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when...
Moderate
Unreviewed
CVE-2026-59354
was published
Aug 27, 2026
A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound...
Moderate
Unreviewed
CVE-2026-47880
was published
Aug 27, 2026
A malicious actor with access to the network and high privileges could exploit an Improper Input...
Critical
Unreviewed
CVE-2026-77540
was published
Aug 27, 2026
A malicious actor with access to the network and high privileges could exploit an Improper Input...
Critical
Unreviewed
CVE-2026-77539
was published
Aug 27, 2026
The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to...
Low
Unreviewed
CVE-2026-56547
was published
Aug 26, 2026
A malicious actor with access to the network and low privileges could exploit an Improper Input...
Critical
Unreviewed
CVE-2026-77533
was published
Aug 26, 2026
Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.
Moderate
Unreviewed
CVE-2026-18261
was published
Aug 26, 2026
Vulnerability in Drupal Disable Login Page. This issue affects Disable Login Page versions: *.*.
Moderate
Unreviewed
CVE-2026-18260
was published
Aug 26, 2026
Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.
Moderate
Unreviewed
CVE-2026-16642
was published
Aug 26, 2026
Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.
Critical
Unreviewed
CVE-2026-16641
was published
Aug 26, 2026
Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*.
Moderate
Unreviewed
CVE-2026-16643
was published
Aug 26, 2026
Vulnerability in Drupal Development Environment. This issue affects Development Environment...
Moderate
Unreviewed
CVE-2026-15088
was published
Aug 26, 2026
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990...
Critical
Unreviewed
CVE-2026-65637
was published
Aug 26, 2026
Improper input validation in Autofill in Google Chrome on on Android prior to 152.0.7977.65...
Moderate
Unreviewed
CVE-2026-79288
was published
Aug 25, 2026
Improper input validation in FindInPage in Google Chrome prior to 152.0.7977.65 allowed a remote...
Low
Unreviewed
CVE-2026-79272
was published
Aug 25, 2026
Improper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65 allowed a...
Unknown
Unreviewed
CVE-2026-79259
was published
Aug 25, 2026
Improper input validation in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote...
Low
Unreviewed
CVE-2026-79255
was published
Aug 25, 2026
Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-79251
was published
Aug 25, 2026
ProTip!
Advisories are also available from the
GraphQL API