GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,582
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
711 advisories
Filter by severity
WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account...
Moderate
Unreviewed
CVE-2026-78617
was published
Aug 28, 2026
Observable discrepancy vulnerability in Seres Software syWEB allows Account Footprinting.
This...
Moderate
Unreviewed
CVE-2026-11754
was published
Aug 27, 2026
Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-79287
was published
Aug 25, 2026
Observable discrepancy in HTML in Google Chrome prior to 152.0.7977.65 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-79242
was published
Aug 25, 2026
Observable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-79181
was published
Aug 25, 2026
Observable discrepancy in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-79030
was published
Aug 25, 2026
Observable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-79028
was published
Aug 25, 2026
Observable discrepancy in SVG in Google Chrome prior to 152.0.7977.65 allowed a remote attacker...
Unknown
Unreviewed
CVE-2026-79016
was published
Aug 25, 2026
Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65...
Unknown
Unreviewed
CVE-2026-78949
was published
Aug 25, 2026
Observable discrepancy in PerformanceAPIs in Google Chrome prior to 152.0.7977.65 allowed a...
Unknown
Unreviewed
CVE-2026-78955
was published
Aug 25, 2026
Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65...
Unknown
Unreviewed
CVE-2026-78936
was published
Aug 25, 2026
The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address...
Critical
Unreviewed
CVE-2026-72699
was published
Aug 25, 2026
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
Low
GHSA-8fxq-53rx-ph5f
was published
for
github.com/coder/coder/v2
(Go)
Aug 20, 2026
Information disclosure due to side-channel in the Storage: Cache API component. This...
High
Unreviewed
CVE-2026-74954
was published
Aug 18, 2026
Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154 and Firefox...
Critical
Unreviewed
CVE-2026-74961
was published
Aug 18, 2026
The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK...
Moderate
Unreviewed
CVE-2026-23937
was published
Aug 18, 2026
The frontend validatate.api.exists action can be exploited by authenticated users to extract...
Moderate
Unreviewed
CVE-2026-23931
was published
Aug 18, 2026
A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the...
Low
Unreviewed
CVE-2026-19965
was published
Aug 17, 2026
SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree...
Moderate
Unreviewed
CVE-2026-73630
was published
Aug 14, 2026
Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via...
High
Unreviewed
CVE-2026-72632
was published
Aug 13, 2026
When Multi-Attribute Login is enabled, the login interface fails to consistently mask the...
Low
Unreviewed
CVE-2025-13736
was published
Aug 6, 2026
In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session...
High
Unreviewed
CVE-2026-59640
was published
Aug 3, 2026
Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows...
Moderate
Unreviewed
CVE-2026-67193
was published
Jul 29, 2026
This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and...
High
Unreviewed
CVE-2026-64713
was published
Jul 27, 2026
ProTip!
Advisories are also available from the
GraphQL API