GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
338 advisories
Filter by severity
sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and...
Moderate
Unreviewed
CVE-2026-97058
was published
Sep 24, 2026
redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing...
High
Unreviewed
CVE-2026-97057
was published
Sep 24, 2026
MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the...
High
Unreviewed
CVE-2026-93345
was published
Sep 22, 2026
Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open...
High
Unreviewed
CVE-2026-89420
was published
Sep 22, 2026
source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source...
High
Unreviewed
CVE-2026-93749
was published
Sep 18, 2026
IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an...
Moderate
Unreviewed
CVE-2025-36178
was published
Sep 18, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure...
High
Unreviewed
CVE-2026-76442
was published
Sep 14, 2026
An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto...
Moderate
Unreviewed
CVE-2024-53922
was published
Sep 14, 2026
t-digest versions 3.1 through 3.3 contain a denial of service vulnerability in MergingDigest...
High
Unreviewed
CVE-2026-87962
was published
Sep 10, 2026
An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an...
Moderate
Unreviewed
CVE-2026-87735
was published
Sep 9, 2026
Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a...
Critical
Unreviewed
CVE-2026-87470
was published
Sep 9, 2026
Improper validation of specified quantity in input vulnerability in PayTR Payment and Electronic...
High
Unreviewed
CVE-2026-16025
was published
Sep 8, 2026
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated...
High
Unreviewed
CVE-2026-82750
was published
Sep 6, 2026
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated...
High
Unreviewed
CVE-2026-82751
was published
Sep 6, 2026
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
High
CVE-2026-82397
was published
for
tornado
(pip)
Sep 2, 2026
Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X...
Critical
Unreviewed
CVE-2026-81779
was published
Aug 31, 2026
DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an...
Moderate
Unreviewed
CVE-2026-59317
was published
Aug 27, 2026
Software installed and run as a non-privileged user may conduct improper GPU system calls to pass...
High
Unreviewed
CVE-2026-45201
was published
Aug 21, 2026
tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream...
Low
Unreviewed
CVE-2026-77640
was published
Aug 20, 2026
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). ...
High
Unreviewed
CVE-2026-60820
was published
Aug 18, 2026
Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size...
High
Unreviewed
CVE-2026-75897
was published
Aug 18, 2026
Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions.
Moderate
Unreviewed
CVE-2026-66679
was published
Aug 18, 2026
An improper access control vulnerability exists where an authenticated non-administrative...
Moderate
Unreviewed
CVE-2026-19639
was published
Aug 14, 2026
Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie...
Moderate
Unreviewed
CVE-2026-19518
was published
Aug 11, 2026
GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory()...
Moderate
Unreviewed
CVE-2026-71394
was published
Aug 10, 2026
ProTip!
Advisories are also available from the
GraphQL API