GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
623 advisories
Filter by severity
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for...
High
Unreviewed
CVE-2026-59641
was published
Aug 3, 2026
Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and...
High
Unreviewed
CVE-2026-67307
was published
Aug 1, 2026
Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS...
Moderate
Unreviewed
CVE-2026-28145
was published
Jul 31, 2026
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing...
High
Unreviewed
CVE-2026-10079
was published
Jul 31, 2026
A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses...
High
Unreviewed
CVE-2026-12383
was published
Jul 27, 2026
OmniFaces: Forged combined-resource IDs and related output/push boundaries
High
GHSA-fp43-vj7g-pg92
was published
for
org.omnifaces:omnifaces
(Maven)
Jul 24, 2026
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
High
GHSA-pvcr-8mvp-w8qr
was published
for
@budibase/server
(npm)
Jul 24, 2026
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
High
GHSA-qq9h-g4jm-xgf3
was published
for
better-auth
(npm)
Jul 24, 2026
Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where...
Moderate
Unreviewed
CVE-2026-39155
was published
Jul 23, 2026
Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling...
Critical
Unreviewed
CVE-2026-15612
was published
Jul 23, 2026
Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and...
High
Unreviewed
CVE-2026-15615
was published
Jul 23, 2026
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
Moderate
GHSA-x445-f3h2-j279
was published
for
@auth/core
(npm)
Jul 23, 2026
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
High
GHSA-8342-988q-86cr
was published
for
n8n
(npm)
Jul 22, 2026
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG...
High
Unreviewed
CVE-2026-44690
was published
Jul 22, 2026
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured...
Moderate
Unreviewed
CVE-2026-50248
was published
Jul 22, 2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be...
Moderate
Unreviewed
CVE-2026-13188
was published
Jul 22, 2026
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component:...
Moderate
Unreviewed
CVE-2026-62517
was published
Jul 22, 2026
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability
High
CVE-2026-47304
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
Moderate
CVE-2026-59930
was published
for
mistune
(pip)
Jul 20, 2026
The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes...
Moderate
Unreviewed
CVE-2026-10724
was published
Jul 20, 2026
The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body...
Moderate
Unreviewed
CVE-2026-12724
was published
Jul 20, 2026
SigNoz through 0.133.0 contains an open redirect vulnerability in the SSO authentication flow...
High
Unreviewed
CVE-2026-63094
was published
Jul 17, 2026
OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas...
Moderate
Unreviewed
CVE-2026-62215
was published
Jul 17, 2026
Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the...
High
Unreviewed
CVE-2026-9561
was published
Jul 14, 2026
The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data...
Moderate
Unreviewed
CVE-2026-11901
was published
Jul 11, 2026
ProTip!
Advisories are also available from the
GraphQL API