GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
145,502 advisories
Filter by severity
Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories()...
High
Unreviewed
CVE-2026-105220
was published
Oct 5, 2026
Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in...
High
Unreviewed
CVE-2026-105219
was published
Oct 4, 2026
ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2...
High
Unreviewed
CVE-2026-105213
was published
Oct 4, 2026
ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted...
High
Unreviewed
CVE-2026-105212
was published
Oct 4, 2026
ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated,...
High
Unreviewed
CVE-2026-105208
was published
Oct 4, 2026
ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the...
High
Unreviewed
CVE-2026-105210
was published
Oct 4, 2026
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator...
High
Unreviewed
CVE-2026-97307
was published
Oct 4, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2026-103062
was published
Oct 4, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2026-103354
was published
Oct 4, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2026-103344
was published
Oct 4, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2026-97276
was published
Oct 4, 2026
Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: before 14.1-73.41,...
High
Unreviewed
CVE-2026-88779
was published
Oct 4, 2026
LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows...
High
Unreviewed
CVE-2026-105126
was published
Oct 4, 2026
LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows...
High
Unreviewed
CVE-2026-105129
was published
Oct 4, 2026
W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that...
High
Unreviewed
CVE-2026-105123
was published
Oct 4, 2026
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member...
High
Unreviewed
CVE-2026-96451
was published
Oct 3, 2026
Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows...
High
Unreviewed
CVE-2026-103065
was published
Oct 3, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2026-103342
was published
Oct 3, 2026
OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests...
High
Unreviewed
CVE-2026-105119
was published
Oct 3, 2026
Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non...
High
Unreviewed
CVE-2026-105113
was published
Oct 3, 2026
OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in...
High
Unreviewed
CVE-2026-105115
was published
Oct 3, 2026
In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made...
High
Unreviewed
CVE-2026-71887
was published
Oct 3, 2026
In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a...
High
Unreviewed
CVE-2026-71888
was published
Oct 3, 2026
In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle...
High
Unreviewed
CVE-2026-71889
was published
Oct 3, 2026
In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so...
High
Unreviewed
CVE-2026-71891
was published
Oct 3, 2026
ProTip!
Advisories are also available from the
GraphQL API