GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,578
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,115 advisories
Filter by severity
A malicious actor with access to the network and high privileges could exploit an Improper Input...
Critical
Unreviewed
CVE-2026-77540
was published
Aug 27, 2026
A malicious actor with access to the network and high privileges could exploit an Improper Input...
Critical
Unreviewed
CVE-2026-77539
was published
Aug 27, 2026
A malicious actor with access to the network and low privileges could exploit an Improper Input...
Critical
Unreviewed
CVE-2026-77533
was published
Aug 26, 2026
Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.
Critical
Unreviewed
CVE-2026-16641
was published
Aug 26, 2026
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990...
Critical
Unreviewed
CVE-2026-65637
was published
Aug 26, 2026
Improper input validation in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote...
Critical
Unreviewed
CVE-2026-79111
was published
Aug 25, 2026
Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote...
Critical
Unreviewed
CVE-2026-78900
was published
Aug 25, 2026
Improper input validation vulnerability in Apache Camel Atmosphere Websocket component.
This...
Critical
Unreviewed
CVE-2026-71300
was published
Aug 24, 2026
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code...
Critical
Unreviewed
CVE-2026-59568
was published
Aug 24, 2026
justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active...
Critical
Unreviewed
CVE-2026-7808
was published
Aug 23, 2026
justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers ...
Critical
Unreviewed
CVE-2026-5388
was published
Aug 23, 2026
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC...
Critical
Unreviewed
CVE-2026-77645
was published
Aug 21, 2026
A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect...
Critical
Unreviewed
CVE-2026-66785
was published
Aug 20, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure...
Critical
Unreviewed
CVE-2026-20318
was published
Aug 19, 2026
Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed...
Critical
Unreviewed
CVE-2026-76035
was published
Aug 18, 2026
jmespath.php has CompilerRuntime code injection via unescaped function names
Critical
CVE-2026-54133
was published
for
mtdowling/jmespath.php
(Composer)
Aug 18, 2026
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0.
Users are...
Critical
Unreviewed
CVE-2026-40920
was published
Aug 10, 2026
Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0
Users are recommended to...
Critical
Unreviewed
CVE-2026-42537
was published
Aug 10, 2026
Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109...
Critical
Unreviewed
CVE-2026-19164
was published
Aug 7, 2026
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash`...
Critical
Unreviewed
CVE-2026-57817
was published
Aug 6, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco...
Critical
Unreviewed
CVE-2026-20303
was published
Aug 5, 2026
OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of...
Critical
Unreviewed
CVE-2026-18801
was published
Aug 4, 2026
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value....
Critical
Unreviewed
CVE-2026-59650
was published
Aug 3, 2026
@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0...
Critical
Unreviewed
CVE-2026-67330
was published
Aug 1, 2026
Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72...
Critical
Unreviewed
CVE-2026-18002
was published
Jul 30, 2026
ProTip!
Advisories are also available from the
GraphQL API