GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
174,752 advisories
Filter by severity
This vulnerability in Veeam Backup & Replication allows a Backup Viewer to modify the Enterprise...
Moderate
Unreviewed
CVE-2026-93026
was published
Oct 7, 2026
The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values...
Moderate
Unreviewed
CVE-2026-86833
was published
Oct 7, 2026
This vulnerability in Veeam Backup Enterprise Manager allows an attacker to execute script in the...
Moderate
Unreviewed
CVE-2025-64392
was published
Oct 7, 2026
This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to...
Moderate
Unreviewed
CVE-2025-64391
was published
Oct 7, 2026
Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4...
Moderate
Unreviewed
CVE-2026-102781
was published
Oct 7, 2026
A flaw was found in the SMTP email configuration handling of the keycloak-services component....
Moderate
Unreviewed
CVE-2026-107121
was published
Oct 7, 2026
This vulnerability in Veeam Agent for Microsoft Windows allows any local user to terminate...
Moderate
Unreviewed
CVE-2026-58068
was published
Oct 7, 2026
The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of...
Moderate
Unreviewed
CVE-2026-105322
was published
Oct 7, 2026
A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from ...
Moderate
Unreviewed
CVE-2026-103870
was published
Oct 7, 2026
A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token...
Moderate
Unreviewed
CVE-2026-103869
was published
Oct 7, 2026
A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and...
Moderate
Unreviewed
CVE-2026-103868
was published
Oct 7, 2026
In wolfSSH through 1.5.0 built with --enable-fwd, DoChannelOpen() in src/internal.c gates only...
Moderate
Unreviewed
CVE-2026-81535
was published
Oct 7, 2026
src/internal.c in wolfSSL wolfSSH through 1.5.0 admits the server-to-client Diffie-Hellman group...
Moderate
Unreviewed
CVE-2026-84897
was published
Oct 7, 2026
Unsigned integer underflow in wstrncat() in src/port.c in wolfSSL wolfSSH from v1.4.11 through v1...
Moderate
Unreviewed
CVE-2026-83742
was published
Oct 7, 2026
A flaw was found in GIMP’s X cursor (XMC) thumbnail loader. When GIMP generates a thumbnail for a...
Moderate
Unreviewed
CVE-2026-106061
was published
Oct 7, 2026
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain...
Moderate
Unreviewed
CVE-2026-97671
was published
Oct 7, 2026
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain...
Moderate
Unreviewed
CVE-2026-93448
was published
Oct 7, 2026
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to cause a...
Moderate
Unreviewed
CVE-2026-93679
was published
Oct 7, 2026
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain...
Moderate
Unreviewed
CVE-2026-101329
was published
Oct 7, 2026
NVIDIA TensorRT contains a vulnerability where an attacker can cause an out of bounds read. A...
Moderate
Unreviewed
CVE-2026-65122
was published
Oct 7, 2026
A heap-based buffer over-read in H5Z__filter_scaleoffset() in src/H5Zscaleoffset.c in HDF5...
Moderate
Unreviewed
CVE-2026-19029
was published
Oct 6, 2026
In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be...
Moderate
Unreviewed
CVE-2026-106552
was published
Oct 6, 2026
In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length...
Moderate
Unreviewed
CVE-2026-106585
was published
Oct 6, 2026
A flaw was found in SSSD (System Security Services Daemon). When Identity Provider (IdP)...
Moderate
Unreviewed
CVE-2026-104046
was published
Oct 6, 2026
A flaw was found in SSSD. A local user can trigger a Denial of Service (DoS) by exploiting a race...
Moderate
Unreviewed
CVE-2026-104045
was published
Oct 6, 2026
ProTip!
Advisories are also available from the
GraphQL API