GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,517
Rust
20
35,887 advisories
Filter by severity
A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is...
Critical
Unreviewed
CVE-2026-105284
was published
Oct 5, 2026
P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank...
Critical
Unreviewed
CVE-2026-103510
was published
Oct 5, 2026
Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a...
Critical
Unreviewed
CVE-2026-100103
was published
Oct 5, 2026
Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug...
Critical
Unreviewed
CVE-2026-100102
was published
Oct 5, 2026
Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that...
Critical
Unreviewed
CVE-2026-105293
was published
Oct 5, 2026
Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script...
Critical
Unreviewed
CVE-2026-105294
was published
Oct 5, 2026
maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in...
Critical
Unreviewed
CVE-2026-105223
was published
Oct 5, 2026
The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification...
Critical
Unreviewed
CVE-2026-105222
was published
Oct 5, 2026
The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that...
Critical
Unreviewed
CVE-2026-105221
was published
Oct 5, 2026
go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows...
Critical
Unreviewed
CVE-2026-105216
was published
Oct 4, 2026
gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client...
Critical
Unreviewed
CVE-2026-105218
was published
Oct 4, 2026
WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows...
Critical
Unreviewed
CVE-2026-105086
was published
Oct 4, 2026
WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users...
Critical
Unreviewed
CVE-2026-105089
was published
Oct 4, 2026
ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login...
Critical
Unreviewed
CVE-2026-105215
was published
Oct 4, 2026
ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability:...
Critical
Unreviewed
CVE-2026-105209
was published
Oct 4, 2026
ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and...
Critical
Unreviewed
CVE-2026-105207
was published
Oct 4, 2026
ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows...
Critical
Unreviewed
CVE-2026-105211
was published
Oct 4, 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2026-103355
was published
Oct 4, 2026
A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function...
Critical
Unreviewed
CVE-2026-105135
was published
Oct 4, 2026
A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of...
Critical
Unreviewed
CVE-2026-105134
was published
Oct 4, 2026
CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and...
Critical
Unreviewed
CVE-2026-105105
was published
Oct 3, 2026
In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420)...
Critical
Unreviewed
CVE-2026-71885
was published
Oct 3, 2026
The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is...
Critical
Unreviewed
CVE-2026-92084
was published
Oct 3, 2026
The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary...
Critical
Unreviewed
CVE-2026-87115
was published
Oct 3, 2026
In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes...
Critical
Unreviewed
CVE-2026-105080
was published
Oct 3, 2026
ProTip!
Advisories are also available from the
GraphQL API