GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,847
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,579
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
48 advisories
Filter by severity
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco...
High
Unreviewed
CVE-2026-20280
was published
Sep 2, 2026
An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit...
High
Unreviewed
CVE-2026-71645
was published
Sep 11, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
High
Unreviewed
CVE-2026-80135
was published
Sep 7, 2026
A missing authorization vulnerability exists in the embedded webserver of HP Deskjet 2800 Series...
High
Unreviewed
CVE-2026-13753
was published
Jul 6, 2026
Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose...
High
Unreviewed
CVE-2026-26446
was published
Aug 26, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS...
High
Unreviewed
CVE-2026-20187
was published
Jul 15, 2026
Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls
High
CVE-2025-14874
was published
for
nodemailer
(Maven)
Dec 1, 2025
Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was...
High
Unreviewed
CVE-2026-12324
was published
Jun 16, 2026
Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length
High
CVE-2026-44893
was published
for
io.netty:netty-codec-haproxy
(Maven)
Jun 8, 2026
XiangShan (Open-source high-performance RISC-V processor) commit...
High
Unreviewed
CVE-2026-29643
was published
Apr 21, 2026
The issue was addressed with improved checks. This issue is fixed in tvOS 17.5, visionOS 1.2, iOS...
High
Unreviewed
CVE-2024-27832
was published
Jun 10, 2024
CometBFT has inconsistencies between how commit signatures are verified and how block time is derived
High
GHSA-c32p-wcqj-j677
was published
for
github.com/cometbft/cometbft
(Go)
Jan 23, 2026
rPGP vulnerable to parser crash on crafted RSA secret key packets through CVE-2026-21895
High
GHSA-7587-4wv6-m68m
was published
for
pgp
(Rust)
Feb 13, 2026
chetans9 core-php-admin-panel through commit a94a780d6 contains an authentication bypass...
High
Unreviewed
CVE-2025-70758
was published
Feb 3, 2026
Emmett-Core: Unhandled CookieError Exception Causing Denial of Service
High
CVE-2026-25577
was published
for
emmett-core
(pip)
Feb 10, 2026
Decidim's private data exports can lead to data leaks
High
CVE-2025-65017
was published
for
decidim
(RubyGems)
Feb 3, 2026
An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds...
High
Unreviewed
CVE-2021-25372
was published
May 24, 2022
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability...
High
Unreviewed
CVE-2025-13016
was published
Nov 11, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook
High
CVE-2025-59538
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Sep 30, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload
High
CVE-2025-59531
was published
for
github.com/argoproj/argo-cd
(Go)
Sep 30, 2025
Under undisclosed traffic conditions along with conditions beyond the attacker's control,...
High
Unreviewed
CVE-2025-58153
was published
Oct 15, 2025
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022...
High
Unreviewed
CVE-2022-22265
was published
Jan 11, 2022
HAX CMS NodeJS Application Has Improper Error Handling That Leads to Denial of Service
High
CVE-2025-54134
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
The DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling...
High
Unreviewed
CVE-2022-41589
was published
Oct 14, 2022
An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It...
High
Unreviewed
CVE-2024-47215
was published
Apr 3, 2025
ProTip!
Advisories are also available from the
GraphQL API