GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
791 advisories
Filter by severity
rclone: http backend forwards custom/auth headers to a different host on redirect
Low
CVE-2026-88013
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP...
High
Unreviewed
CVE-2026-81330
was published
Sep 9, 2026
Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to 153...
Moderate
Unreviewed
CVE-2026-87482
was published
Sep 9, 2026
U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration...
Moderate
Unreviewed
CVE-2026-79588
was published
Sep 8, 2026
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
High
CVE-2026-84381
was published
for
httpcore2
(pip)
Sep 8, 2026
PagerDuty alarm hook transmits the integration routing key over cleartext HTTP.
PagerDuty...
Moderate
Unreviewed
CVE-2026-71216
was published
Sep 4, 2026
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
High
CVE-2026-84366
was published
for
scrapy
(pip)
Sep 2, 2026
A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to...
Moderate
Unreviewed
CVE-2026-73756
was published
Sep 1, 2026
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could...
Low
Unreviewed
CVE-2026-73743
was published
Sep 1, 2026
pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
High
GHSA-vx52-2968-3vc6
was published
for
pnpm
(npm)
Sep 1, 2026
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
Moderate
CVE-2026-55860
was published
for
org.mariadb:r2dbc-mariadb
(Maven)
Aug 28, 2026
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
Moderate
CVE-2026-55857
was published
for
org.mariadb.jdbc:mariadb-java-client
(Maven)
Aug 28, 2026
MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
Moderate
CVE-2026-55854
was published
for
mariadb
(npm)
Aug 28, 2026
A cleartext transmission of sensitive information vulnerability exists
in certain Ebyte gateway...
High
Unreviewed
CVE-2026-73809
was published
Aug 28, 2026
MQTT credentials and control traffic are transmitted in cleartext,
exposing sensitive...
Critical
Unreviewed
CVE-2026-69658
was published
Aug 28, 2026
openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and...
High
Unreviewed
CVE-2026-81691
was published
Aug 27, 2026
When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks...
Moderate
Unreviewed
CVE-2026-19854
was published
Aug 27, 2026
A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple...
High
Unreviewed
CVE-2026-29988
was published
Aug 26, 2026
rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing...
Moderate
Unreviewed
CVE-2026-79779
was published
Aug 25, 2026
rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes...
Critical
Unreviewed
CVE-2026-79782
was published
Aug 25, 2026
When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in...
Moderate
Unreviewed
CVE-2026-77131
was published
Aug 25, 2026
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions...
High
Unreviewed
CVE-2026-12556
was published
Aug 24, 2026
A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During...
Moderate
Unreviewed
CVE-2026-19683
was published
Aug 20, 2026
Download of code without integrity check, inclusion of functionality from untrusted control...
Critical
Unreviewed
CVE-2026-22306
was published
Aug 19, 2026
stigmem-node contains an insecure default configuration vulnerability that allows federation...
Critical
Unreviewed
CVE-2026-76244
was published
Aug 19, 2026
ProTip!
Advisories are also available from the
GraphQL API