GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
55
Go
4,533
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
507 advisories
Filter by severity
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key...
Critical
Unreviewed
CVE-2026-74889
was published
Aug 17, 2026
Inadequate encryption strength in Windows Active Directory allows an authorized attacker to...
Moderate
Unreviewed
CVE-2026-65777
was published
Aug 11, 2026
IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary...
High
Unreviewed
CVE-2026-9201
was published
Aug 5, 2026
In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity...
High
Unreviewed
CVE-2026-59651
was published
Aug 3, 2026
Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands...
Moderate
Unreviewed
CVE-2026-4648
was published
Jul 28, 2026
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength...
High
Unreviewed
CVE-2026-50044
was published
Jul 24, 2026
HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of...
Critical
Unreviewed
CVE-2024-23564
was published
Jul 17, 2026
HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits...
Moderate
Unreviewed
CVE-2026-35146
was published
Jul 16, 2026
The encryption algorithm used to protect the configuration of user accounts, stored in the built...
High
Unreviewed
CVE-2026-14868
was published
Jul 7, 2026
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
High
CVE-2026-49852
was published
for
joserfc
(pip)
Jul 2, 2026
UltraVNC through 1.8.2.2 uses inadequate cryptography in the MS-Logon II authentication scheme ...
High
Unreviewed
CVE-2026-7830
was published
Jul 1, 2026
CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token...
High
Unreviewed
CVE-2026-41860
was published
Jun 4, 2026
Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that...
High
Unreviewed
CVE-2026-8878
was published
Jun 3, 2026
ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351
High
CVE-2026-45363
was published
for
jwt
(RubyGems)
May 18, 2026
slack-go `SecretsVerifier` accepts empty signing secret without precondition
Moderate
GHSA-gxhx-2686-5h9g
was published
for
github.com/slack-go/slack
(Go)
May 14, 2026
electerm's encrypt method not safe enough
Moderate
CVE-2026-45787
was published
for
electerm
(npm)
May 14, 2026
In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220),...
High
Unreviewed
CVE-2026-33361
was published
May 11, 2026
Note Mark has a JWT Secret Weakness that allows Full Account Takeover via Token Forgery
Critical
CVE-2026-44523
was published
for
github.com/enchant97/note-mark/backend
(Go)
May 7, 2026
fast-jwt: JWT auth bypass due to empty HMAC secret accepted by async key resolver
Critical
CVE-2026-44351
was published
for
fast-jwt
(npm)
May 6, 2026
ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain...
Critical
Unreviewed
CVE-2018-25272
was published
Apr 22, 2026
Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior...
Moderate
Unreviewed
CVE-2025-1241
was published
Apr 21, 2026
Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules)...
Moderate
Unreviewed
CVE-2026-5363
was published
Apr 16, 2026
Cryptographic Flaw in PDFium in Google Chrome prior to 147.0.7727.55 allowed an attacker to read...
Moderate
Unreviewed
CVE-2026-5889
was published
Apr 9, 2026
Grafana Tempo has Inadequate Encryption Strength
High
CVE-2026-28377
was published
for
github.com/grafana/tempo
(Go)
Mar 27, 2026
AVideo has an unauthenticated decrypt oracle leaking any ciphertext
High
CVE-2026-33512
was published
for
wwbn/avideo
(Composer)
Mar 20, 2026
ProTip!
Advisories are also available from the
GraphQL API