GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
5,885 advisories
Filter by severity
Shopper: Negative discount values accepted and propagated through order calculation pipeline
Moderate
CVE-2026-56831
was published
for
shopper/framework
(Composer)
Sep 11, 2026
The product's web portals allow external links to be opened in a new browser tab. In certain...
Moderate
Unreviewed
CVE-2026-3096
was published
Sep 10, 2026
A vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) thru 1.4.0 allows local...
Moderate
Unreviewed
CVE-2025-51619
was published
Sep 9, 2026
An issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial of service via a crafted...
Moderate
Unreviewed
CVE-2026-39020
was published
Sep 9, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
Moderate
CVE-2026-54529
was published
for
sqladmin
(pip)
Sep 9, 2026
Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing...
Moderate
Unreviewed
CVE-2026-86768
was published
Sep 9, 2026
A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p...
Moderate
Unreviewed
CVE-2025-7062
was published
Sep 9, 2026
Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch...
Moderate
Unreviewed
CVE-2026-21112
was published
Sep 9, 2026
Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to...
Moderate
Unreviewed
CVE-2026-21086
was published
Sep 9, 2026
Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026...
Moderate
Unreviewed
CVE-2026-21088
was published
Sep 9, 2026
Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026...
Moderate
Unreviewed
CVE-2026-21089
was published
Sep 9, 2026
Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent...
Moderate
Unreviewed
CVE-2026-21094
was published
Sep 9, 2026
A weakness has been identified in tile-ai tilelang up to 0.1.14. This impacts the function...
Moderate
Unreviewed
CVE-2026-87083
was published
Sep 9, 2026
Improper input validation in Interstitials in Google Chrome prior to 153.0.8010.36 allowed a...
Moderate
Unreviewed
CVE-2026-87599
was published
Sep 9, 2026
Improper input validation in Network in Google Chrome prior to 153.0.8010.36 allowed a remote...
Moderate
Unreviewed
CVE-2026-87573
was published
Sep 9, 2026
Improper input validation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote...
Moderate
Unreviewed
CVE-2026-87590
was published
Sep 9, 2026
Improper input validation in Safebrowsing in Google Chrome on on Android prior to 153.0.8010.36...
Moderate
Unreviewed
CVE-2026-87600
was published
Sep 9, 2026
Improper input validation in Chromium in Google Chrome prior to 153.0.8010.36 allowed a remote...
Moderate
Unreviewed
CVE-2026-87568
was published
Sep 9, 2026
Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote...
Moderate
Unreviewed
CVE-2026-87472
was published
Sep 9, 2026
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
Moderate
GHSA-wmmp-3585-3rmp
was published
for
nodemailer
(npm)
Sep 8, 2026
Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
Moderate
GHSA-cc9r-2j5m-2m83
was published
for
nodemailer
(npm)
Sep 8, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose...
Moderate
Unreviewed
CVE-2026-81392
was published
Sep 8, 2026
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose...
Moderate
Unreviewed
CVE-2026-72977
was published
Sep 8, 2026
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker...
Moderate
Unreviewed
CVE-2026-69286
was published
Sep 8, 2026
Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly...
Moderate
Unreviewed
CVE-2026-86440
was published
Sep 7, 2026
ProTip!
Advisories are also available from the
GraphQL API