GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
388 advisories
Filter by severity
Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon...
Moderate
Unreviewed
CVE-2026-89332
was published
Sep 11, 2026
Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows...
Moderate
Unreviewed
CVE-2026-62088
was published
Sep 11, 2026
Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication
Moderate
CVE-2026-87015
was published
for
open-webui
(pip)
Sep 10, 2026
Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2...
High
Unreviewed
CVE-2026-81804
was published
Sep 10, 2026
Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking...
Moderate
Unreviewed
CVE-2026-78303
was published
Sep 10, 2026
Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder...
Moderate
Unreviewed
CVE-2026-78374
was published
Sep 10, 2026
Insertion of sensitive information into sent data in Microsoft Teams for Android allows an...
Moderate
Unreviewed
CVE-2026-65812
was published
Sep 8, 2026
In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication...
Moderate
Unreviewed
CVE-2026-86497
was published
Sep 7, 2026
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to...
Low
Unreviewed
CVE-2026-86505
was published
Sep 7, 2026
A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of
space (ascii code 32)...
High
Unreviewed
CVE-2026-80255
was published
Sep 6, 2026
When libpsl support is enabled, libcurl fails to enforce the Public Suffix
List boundary check...
High
Unreviewed
CVE-2026-82209
was published
Sep 6, 2026
Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready...
Moderate
Unreviewed
CVE-2026-85307
was published
Sep 3, 2026
Hurl: Cookies in Cookies section leak when redirecting to a different host
Moderate
CVE-2026-63481
was published
for
hurl
(Rust)
Sep 2, 2026
Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability...
Moderate
Unreviewed
CVE-2026-77123
was published
Sep 2, 2026
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best...
Moderate
Unreviewed
CVE-2026-81162
was published
Sep 2, 2026
pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
High
GHSA-vx52-2968-3vc6
was published
for
pnpm
(npm)
Sep 1, 2026
Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <...
Moderate
Unreviewed
CVE-2026-81280
was published
Aug 31, 2026
urllib's cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage
High
CVE-2026-55553
was published
for
urllib
(npm)
Aug 25, 2026
Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.
High
Unreviewed
CVE-2026-66585
was published
Aug 24, 2026
SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the...
Moderate
Unreviewed
CVE-2026-59809
was published
Aug 22, 2026
Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient...
High
Unreviewed
CVE-2026-75953
was published
Aug 19, 2026
Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
High
Unreviewed
CVE-2026-73384
was published
Aug 19, 2026
Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0...
High
Unreviewed
CVE-2026-73386
was published
Aug 19, 2026
Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17...
Moderate
Unreviewed
CVE-2026-74008
was published
Aug 18, 2026
Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.
High
Unreviewed
CVE-2026-66463
was published
Aug 13, 2026
ProTip!
Advisories are also available from the
GraphQL API