GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
17,522 advisories
Filter by severity
In sshd in OpenSSH before 10.6, the value "none" for a configuration option is sometimes...
Low
Unreviewed
CVE-2026-106587
was published
Oct 7, 2026
In ssh in OpenSSH before 10.6, a $ or \ character can occur in a command-line username, leading...
Low
Unreviewed
CVE-2026-106583
was published
Oct 7, 2026
In sshd in OpenSSH through 10.6, in certain environments such as QNX 6 and SCO OpenServer 5, sshd...
Low
Unreviewed
CVE-2026-106589
was published
Oct 7, 2026
In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the side effect of loss...
Low
Unreviewed
CVE-2026-106588
was published
Oct 7, 2026
In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be...
Low
Unreviewed
CVE-2026-106555
was published
Oct 6, 2026
In sshd in OpenSSH before 10.6, credentials can incorrectly persist after failure of a...
Low
Unreviewed
CVE-2026-106553
was published
Oct 6, 2026
In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used even though this is...
Low
Unreviewed
CVE-2026-106582
was published
Oct 6, 2026
In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be...
Low
Unreviewed
CVE-2026-106586
was published
Oct 6, 2026
In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because...
Low
Unreviewed
CVE-2026-106584
was published
Oct 6, 2026
Improper neutralization of input during web page generation ('cross-site scripting')...
Low
Unreviewed
CVE-2026-105111
was published
Oct 6, 2026
On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific...
Low
Unreviewed
CVE-2026-102164
was published
Oct 6, 2026
A vulnerability was detected in SourceCodester Performance Indicator System 1.0. The affected...
Low
Unreviewed
CVE-2026-105957
was published
Oct 6, 2026
Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests
Low
CVE-2026-105795
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Oct 6, 2026
i18next-http-backend incomplete URL validation permits SSRF
Low
CVE-2026-105800
was published
for
i18next-http-backend
(npm)
Oct 6, 2026
LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values
Low
CVE-2026-105799
was published
for
@langchain/redis
(npm)
Oct 6, 2026
A vulnerability was identified in Kusalkasilva Learning-Management-System up to...
Low
Unreviewed
CVE-2026-105921
was published
Oct 6, 2026
A security flaw has been discovered in vllm-project vLLM up to 0.31.0. This impacts the function...
Low
Unreviewed
CVE-2026-105922
was published
Oct 6, 2026
HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which...
Low
Unreviewed
CVE-2026-56596
was published
Oct 6, 2026
GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in...
Low
Unreviewed
CVE-2026-75820
was published
Oct 6, 2026
GNU Aspell contains an out-of-bounds read vulnerability in ReadOnlyDict::load() in readonly_ws...
Low
Unreviewed
CVE-2026-75819
was published
Oct 6, 2026
GNU Aspell prezip-bin contains a heap-based buffer overflow vulnerability in the decompressor in...
Low
Unreviewed
CVE-2026-75818
was published
Oct 6, 2026
A vulnerability was identified in SourceCodester Simple Student Information System 1.0. This...
Low
Unreviewed
CVE-2026-105809
was published
Oct 6, 2026
A vulnerability was determined in SourceCodester Simple Student Information System 1.0. This...
Low
Unreviewed
CVE-2026-105808
was published
Oct 6, 2026
A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the...
Low
Unreviewed
CVE-2026-105775
was published
Oct 6, 2026
A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function...
Low
Unreviewed
CVE-2026-105621
was published
Oct 6, 2026
ProTip!
Advisories are also available from the
GraphQL API