GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
387 advisories
Filter by severity
A format string vulnerability exists in the command line interface of AOS-CX that could lead to...
High
Unreviewed
CVE-2026-73782
was published
Sep 1, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated...
High
Unreviewed
CVE-2026-16821
was published
Aug 29, 2026
In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings...
High
Unreviewed
CVE-2026-81574
was published
Aug 27, 2026
Issue summary: OpenSSL CMP response validation passed an unexpected response
sender distinguished...
Critical
Unreviewed
CVE-2026-63073
was published
Aug 25, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2026-17136
was published
Aug 21, 2026
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80...
Moderate
Unreviewed
CVE-2026-15961
was published
Aug 19, 2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0...
High
Unreviewed
CVE-2026-12004
was published
Aug 12, 2026
A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs...
High
Unreviewed
CVE-2026-18188
was published
Jul 30, 2026
A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability...
High
Unreviewed
CVE-2026-18187
was published
Jul 30, 2026
A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability...
High
Unreviewed
CVE-2026-18186
was published
Jul 30, 2026
A format string vulnerability was found in the Notification OAuth settings of ADM. The...
High
Unreviewed
CVE-2026-67244
was published
Jul 30, 2026
A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple...
Moderate
Unreviewed
CVE-2026-6390
was published
Jul 23, 2026
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception:...
Critical
Unreviewed
CVE-2024-58366
was published
Jul 18, 2026
A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect,...
High
Unreviewed
CVE-2026-15809
was published
Jul 15, 2026
Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution...
High
Unreviewed
CVE-2026-15680
was published
Jul 14, 2026
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0...
Moderate
Unreviewed
CVE-2026-46465
was published
Jul 3, 2026
An unauthenticated
format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and
GV...
High
Unreviewed
CVE-2026-57877
was published
Jun 26, 2026
A format string vulnerability has been found in the "alias" parameter of the Serial Param...
Moderate
Unreviewed
CVE-2026-10828
was published
Jun 16, 2026
Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized...
Moderate
Unreviewed
CVE-2025-10262
was published
Jun 16, 2026
An
authenticated format string vulnerability exists in the ONVIF service of Tapo
C110 v2 due to...
High
Unreviewed
CVE-2026-6250
was published
Jun 12, 2026
An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS...
Moderate
Unreviewed
CVE-2026-6242
was published
Jun 6, 2026
An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2,...
Moderate
Unreviewed
CVE-2026-6241
was published
Jun 6, 2026
Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail...
High
Unreviewed
CVE-2026-50211
was published
Jun 4, 2026
A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated...
Low
Unreviewed
CVE-2026-7835
was published
May 21, 2026
Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to...
Moderate
Unreviewed
CVE-2026-6474
was published
May 14, 2026
ProTip!
Advisories are also available from the
GraphQL API