GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,569
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,522
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
168,531 advisories
Filter by severity
vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
Moderate
GHSA-fx4f-mhw4-qm7j
was published
for
vibeio-http
(Rust)
Aug 24, 2026
Cloudreve's remote download file paths can escape the selected destination directory
Moderate
GHSA-w8j7-39hp-8x59
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Aug 24, 2026
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
Moderate
GHSA-vx2m-jpxr-xv7w
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Aug 24, 2026
A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an...
Moderate
Unreviewed
CVE-2026-5006
was published
Aug 24, 2026
Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an...
Moderate
Unreviewed
CVE-2026-77923
was published
Aug 24, 2026
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled...
Moderate
Unreviewed
CVE-2026-16781
was published
Aug 24, 2026
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds...
Moderate
Unreviewed
CVE-2026-16782
was published
Aug 24, 2026
The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own...
Moderate
Unreviewed
CVE-2026-72705
was published
Aug 24, 2026
The guard checker in Rocq Prover does not recheck the recursive tree representation of an...
Moderate
Unreviewed
CVE-2026-72704
was published
Aug 24, 2026
The Lean 4 kernel does not check that the body of an opaque declaration is closed. environment:...
Moderate
Unreviewed
CVE-2026-72711
was published
Aug 24, 2026
Rocq Prover does not restore the universe graph's copy of the universe checking flag when a...
Moderate
Unreviewed
CVE-2026-72714
was published
Aug 24, 2026
Print Assumptions does not report that a definition was produced while universe checking was...
Moderate
Unreviewed
CVE-2020-37268
was published
Aug 24, 2026
The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform...
Moderate
Unreviewed
CVE-2026-72703
was published
Aug 24, 2026
Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following')...
Moderate
Unreviewed
CVE-2026-63693
was published
Aug 24, 2026
Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra...
Moderate
Unreviewed
CVE-2026-71503
was published
Aug 24, 2026
Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key
Moderate
GHSA-w67g-5rqw-f597
was published
for
github.com/gorilla/websocket
(Go)
Aug 24, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
Moderate
CVE-2026-54625
was published
for
django-cms
(pip)
Aug 24, 2026
tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service
Moderate
GHSA-3gjw-f78c-vvpw
was published
for
tokio-postgres
(Rust)
Aug 24, 2026
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
Moderate
GHSA-rgqc-3x5p-6gwg
was published
for
postgres-protocol
(Rust)
Aug 24, 2026
Sakai Profile Image Deletion has an IDOR
Moderate
CVE-2026-54050
was published
for
org.sakaiproject.profile2:profile2-api
(Maven)
Aug 24, 2026
Baserow interpolates a user's display name into the rich-text mention markup without HTML...
Moderate
Unreviewed
CVE-2026-76837
was published
Aug 24, 2026
A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX...
Moderate
Unreviewed
CVE-2026-78475
was published
Aug 24, 2026
Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the...
Moderate
Unreviewed
CVE-2026-71932
was published
Aug 24, 2026
Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the...
Moderate
Unreviewed
CVE-2026-71920
was published
Aug 24, 2026
Improper neutralization of input during web page generation ('cross-site scripting')...
Moderate
Unreviewed
CVE-2026-34491
was published
Aug 24, 2026
ProTip!
Advisories are also available from the
GraphQL API