GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
17,452 advisories
Filter by severity
A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected...
Low
Unreviewed
CVE-2026-104052
was published
Oct 2, 2026
A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted...
Low
Unreviewed
CVE-2026-104053
was published
Oct 2, 2026
A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function...
Low
Unreviewed
CVE-2026-104054
was published
Oct 2, 2026
A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not...
Low
Unreviewed
CVE-2026-5419
was published
Jun 1, 2026
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML...
Low
Unreviewed
CVE-2025-6170
was published
Jun 16, 2025
Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some...
Low
Unreviewed
CVE-2026-42356
was published
Oct 1, 2026
A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the...
Low
Unreviewed
CVE-2026-103113
was published
Sep 30, 2026
HCL BigFix Service Management is affected by an Information Disclosure vulnerability the...
Low
Unreviewed
CVE-2026-67172
was published
Oct 1, 2026
A flaw has been found in itsourcecode Leave Management System 1.0. This vulnerability affects...
Low
Unreviewed
CVE-2026-103690
was published
Oct 1, 2026
HCL AION is affected by a vulnerability in which the Content-Security-Policy (CSP) HTTP response...
Low
Unreviewed
CVE-2026-21833
was published
Oct 1, 2026
A flaw has been found in rhukster dom-sanitizer up to 1.0.15. Impacted is the function...
Low
Unreviewed
CVE-2026-103686
was published
Oct 1, 2026
HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration...
Low
Unreviewed
CVE-2026-56599
was published
Oct 1, 2026
iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker...
Low
Unreviewed
CVE-2026-66249
was published
Oct 1, 2026
iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit...
Low
Unreviewed
CVE-2026-66253
was published
Oct 1, 2026
iControl is affected by an Improper Error Handling vulnerability, which could allow an...
Low
Unreviewed
CVE-2026-66248
was published
Oct 1, 2026
Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in...
Low
Unreviewed
CVE-2026-94220
was published
Oct 1, 2026
Duplicate Advisory: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
Low
GHSA-8mvv-mcc3-xwhh
was published
for
vm2
(npm)
Sep 17, 2026
•
withdrawn
devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated
Low
GHSA-wf3x-273g-mvxv
was published
for
devalue
(npm)
Oct 1, 2026
The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name...
Low
Unreviewed
CVE-2026-87973
was published
Oct 1, 2026
A flaw was found in tnef. A heap-based buffer overflow can occur in the find_free_number()...
Low
Unreviewed
CVE-2026-103680
was published
Oct 1, 2026
In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was...
Low
Unreviewed
CVE-2026-103489
was published
Oct 1, 2026
A vulnerability was found in datadrivenconstruction OpenConstructionERP up to 14.8.1. The...
Low
Unreviewed
CVE-2026-103544
was published
Oct 1, 2026
In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to...
Low
Unreviewed
CVE-2026-0016
was published
Jun 2, 2026
A vulnerability was detected in formtools.org Form Tools up to 3.1.1. This issue affects the...
Low
Unreviewed
CVE-2026-103541
was published
Oct 1, 2026
A security vulnerability has been detected in formtools.org Form Tools up to 3.1.1. This...
Low
Unreviewed
CVE-2026-103540
was published
Oct 1, 2026
ProTip!
Advisories are also available from the
GraphQL API