GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
55
Go
4,531
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
715 advisories
Filter by severity
VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
Critical
CVE-2026-47686
was published
for
vm2
(npm)
Aug 17, 2026
openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process...
Critical
Unreviewed
CVE-2026-74895
was published
Aug 17, 2026
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the...
Critical
Unreviewed
CVE-2026-74896
was published
Aug 17, 2026
openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin...
High
Unreviewed
CVE-2026-74883
was published
Aug 17, 2026
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter...
Critical
Unreviewed
CVE-2026-74790
was published
Aug 16, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass...
Moderate
Unreviewed
CVE-2026-17079
was published
Aug 14, 2026
A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin...
High
Unreviewed
CVE-2026-18428
was published
Aug 13, 2026
A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker...
Moderate
Unreviewed
CVE-2026-0293
was published
Aug 13, 2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections...
Critical
Unreviewed
CVE-2025-59326
was published
Aug 12, 2026
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
Moderate
CVE-2026-62902
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-arm64
(NuGet)
Aug 11, 2026
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a...
High
Unreviewed
CVE-2026-69278
was published
Aug 11, 2026
Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension...
High
Unreviewed
CVE-2026-54981
was published
Aug 11, 2026
Protection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within...
Moderate
Unreviewed
CVE-2026-39452
was published
Aug 11, 2026
Protection mechanism failure for some Intel(R) LLM Library for PyTorch within Ring 3: User...
Moderate
Unreviewed
CVE-2026-21387
was published
Aug 11, 2026
Protection mechanism failure for some Intel(R) AI Reference Models before version v3.4.1 within...
Moderate
Unreviewed
CVE-2026-21400
was published
Aug 11, 2026
Protection mechanism failure for some Intel(R) oneCCL Bindings for PyTorch before version v2.8.0...
Moderate
Unreviewed
CVE-2026-24693
was published
Aug 11, 2026
Protection mechanism failure for some LLM-on-Ray before version 1.0 within Ring 3: User...
Moderate
Unreviewed
CVE-2026-28707
was published
Aug 11, 2026
Protection mechanism failure for some Intel(R) Workload Services Framework software within Ring 3...
Moderate
Unreviewed
CVE-2026-28757
was published
Aug 11, 2026
Protection mechanism failure for some Cluster Management Toolkit for Kubernetes software before...
Moderate
Unreviewed
CVE-2026-20770
was published
Aug 11, 2026
Protection mechanism failure for some Intel(R) AI Containers before version v0.4.0 within Ring 3:...
Moderate
Unreviewed
CVE-2026-20903
was published
Aug 11, 2026
Protection mechanism failure for some Intel(R) Neural Compressor software before version v3.6...
Moderate
Unreviewed
CVE-2026-20906
was published
Aug 11, 2026
Protection mechanism failure for some Intel Extension for TensorFlow software before version 2.15...
Moderate
Unreviewed
CVE-2026-20728
was published
Aug 11, 2026
Protection mechanism failure for some LLM Scaler software within Ring 3: User Applications may...
Moderate
Unreviewed
CVE-2026-20755
was published
Aug 11, 2026
Protection mechanism failure for some Intel(R) Data Center Attestation Primitives (Intel(R) DCAP)...
High
Unreviewed
CVE-2026-20702
was published
Aug 11, 2026
Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote...
High
Unreviewed
CVE-2026-72781
was published
Aug 11, 2026
ProTip!
Advisories are also available from the
GraphQL API