GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
337 advisories
Filter by severity
Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a...
High
Unreviewed
CVE-2026-85053
was published
Sep 3, 2026
Duplicate Advisory: Craft CMS: Authenticated leak of secret environment variables
High
GHSA-cc2g-26rw-g997
was published
for
craftcms/cms
(Composer)
Aug 11, 2026
•
withdrawn
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
High
CVE-2026-53657
was published
for
github.com/lima-vm/lima/v2
(Go)
Aug 14, 2026
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
High
CVE-2026-67427
was published
for
flyto-core
(pip)
Jul 30, 2026
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
High
CVE-2026-54727
was published
for
proot-distro
(pip)
Jul 29, 2026
OpenShift GitOps Operator Namespace Isolation Break
High
CVE-2024-13484
was published
for
github.com/redhat-developer/gitops-operator
(Go)
Jan 28, 2025
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
High
CVE-2026-54096
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
runc vulnerable to container breakout through process.cwd trickery and leaked fds
High
CVE-2024-21626
was published
for
github.com/opencontainers/runc
(Go)
Jan 31, 2024
PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
High
CVE-2026-57144
was published
for
praisonai
(pip)
Jun 18, 2026
@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default
High
CVE-2026-54504
was published
for
@andrea9293/mcp-documentation-server
(npm)
Jul 15, 2026
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2...
High
Unreviewed
CVE-2026-59835
was published
Jul 14, 2026
A Denial Of Service vulnerability exists in PcVue from version 8.10 onward, due to the ability...
High
Unreviewed
CVE-2020-26868
was published
May 24, 2022
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct...
High
Unreviewed
CVE-2021-42641
was published
Feb 9, 2022
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.
High
Unreviewed
CVE-2022-23345
was published
Mar 22, 2022
Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an...
High
Unreviewed
CVE-2021-46354
was published
Feb 10, 2022
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via ...
High
Unreviewed
CVE-2021-40639
was published
May 24, 2022
In IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can...
High
Unreviewed
CVE-2022-24139
was published
Jul 7, 2022
Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could...
High
Unreviewed
CVE-2025-54502
was published
Apr 16, 2026
PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger...
High
Unreviewed
CVE-2026-56077
was published
Jun 19, 2026
Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications
High
CVE-2026-28779
was published
for
apache-airflow
(pip)
Mar 17, 2026
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR...
High
Unreviewed
CVE-2023-26243
was published
Apr 27, 2023
Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local...
High
Unreviewed
CVE-2025-15653
was published
Jun 3, 2026
In the Linux kernel, the following vulnerability has been resolved:
riscv: fgraph: Fix stack...
High
Unreviewed
CVE-2025-22069
was published
Apr 16, 2025
Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated
remote attacker to...
High
Unreviewed
CVE-2023-35696
was published
Jul 10, 2023
Symfony has Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener
High
CVE-2026-45077
was published
for
symfony/monolog-bridge
(Composer)
May 27, 2026
ProTip!
Advisories are also available from the
GraphQL API