GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,830
Maven
5,000+
npm
5,000+
NuGet
1,126
pip
5,000+
Pub
13
RubyGems
1,155
Rust
1,577
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,512
Rust
20
1,600 advisories
Filter by severity
Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability...
High
Unreviewed
CVE-2026-18270
was published
Aug 20, 2026
In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify...
High
Unreviewed
CVE-2026-76399
was published
Aug 20, 2026
In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk...
High
Unreviewed
CVE-2026-76388
was published
Aug 20, 2026
In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks...
Low
Unreviewed
CVE-2026-76371
was published
Aug 20, 2026
In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run...
Moderate
Unreviewed
CVE-2026-76372
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role...
Moderate
Unreviewed
CVE-2026-76260
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway...
Moderate
Unreviewed
CVE-2026-76261
was published
Aug 20, 2026
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
Critical
GHSA-m5w8-4gq2-6f8x
was published
for
vm2
(npm)
Aug 17, 2026
A security vulnerability has been identified in Planet9 due to incorrect file permissions...
High
Unreviewed
CVE-2026-50602
was published
Aug 17, 2026
A maliciously created executable, when executed on the victim's machine, may allow a local low...
High
Unreviewed
CVE-2026-14478
was published
Aug 12, 2026
Incorrect directory permissions could allow a local user to escalate their privileges,...
High
Unreviewed
CVE-2025-0046
was published
Aug 11, 2026
Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized...
High
Unreviewed
CVE-2026-63522
was published
Aug 11, 2026
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The...
High
Unreviewed
CVE-2026-69108
was published
Aug 11, 2026
A VAPIX API parameter had improper input validation which could allow code execution and...
High
Unreviewed
CVE-2026-4757
was published
Aug 11, 2026
A flaw was found in libvirt. During storage volume clone or convert operations, newly created...
Moderate
Unreviewed
CVE-2026-63623
was published
Aug 10, 2026
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
Low
GHSA-945v-v9p3-v5xw
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with...
Moderate
Unreviewed
CVE-2026-68563
was published
Jul 31, 2026
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption
High
CVE-2026-50570
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
A permissions issue was addressed with improved validation. This issue is fixed in iOS 26.6 and...
Moderate
Unreviewed
CVE-2026-64707
was published
Jul 27, 2026
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
High
Unreviewed
CVE-2026-61892
was published
Jul 25, 2026
AWS CLI: Overly permissive File Permissions
Moderate
CVE-2026-13769
was published
for
awscli
(pip)
Jul 24, 2026
Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to...
High
Unreviewed
CVE-2026-16157
was published
Jul 22, 2026
FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes...
High
Unreviewed
CVE-2026-63358
was published
Jul 21, 2026
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
High
CVE-2026-58424
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: draft release attachment disclosure via missing web authorization
Moderate
CVE-2026-58432
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API