GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
6,623 advisories
Filter by severity
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR...
Critical
Unreviewed
CVE-2026-20279
was published
Sep 2, 2026
Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity...
High
Unreviewed
CVE-2026-84668
was published
Sep 2, 2026
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for...
Moderate
Unreviewed
CVE-2026-84651
was published
Sep 2, 2026
Kimai before 2.65.0 fails to properly validate permissions when removing team access to...
Moderate
Unreviewed
CVE-2026-84804
was published
Sep 2, 2026
A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor...
Moderate
Unreviewed
CVE-2026-73762
was published
Sep 1, 2026
Vulnerabilities exist in the authentication module that may improperly process malformed or...
High
Unreviewed
CVE-2026-73750
was published
Sep 1, 2026
Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of...
Critical
Unreviewed
CVE-2026-73749
was published
Sep 1, 2026
Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low...
Moderate
Unreviewed
CVE-2026-73727
was published
Sep 1, 2026
A vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low...
Moderate
Unreviewed
CVE-2026-73741
was published
Sep 1, 2026
When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly...
High
Unreviewed
CVE-2026-18664
was published
Sep 1, 2026
An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via...
Critical
Unreviewed
CVE-2026-52111
was published
Sep 1, 2026
A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMMS prior to v1.6.0....
High
Unreviewed
CVE-2026-51956
was published
Sep 1, 2026
A vulnerability exists in the affected products that allows a threat actor to create a project...
High
Unreviewed
CVE-2024-7953
was published
Sep 1, 2026
Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu...
Critical
Unreviewed
CVE-2026-51770
was published
Sep 1, 2026
Incorrect access control in the setElinkQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015...
High
Unreviewed
CVE-2026-51768
was published
Sep 1, 2026
Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu...
Critical
Unreviewed
CVE-2026-51769
was published
Sep 1, 2026
Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows...
High
Unreviewed
CVE-2026-51766
was published
Sep 1, 2026
Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015...
Moderate
Unreviewed
CVE-2026-51752
was published
Sep 1, 2026
Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015...
Critical
Unreviewed
CVE-2026-51750
was published
Sep 1, 2026
Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015...
Critical
Unreviewed
CVE-2026-51751
was published
Sep 1, 2026
Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu...
Moderate
Unreviewed
CVE-2026-51748
was published
Sep 1, 2026
Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015...
Critical
Unreviewed
CVE-2026-51760
was published
Sep 1, 2026
Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu...
Critical
Unreviewed
CVE-2026-51765
was published
Sep 1, 2026
Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015...
Moderate
Unreviewed
CVE-2026-51756
was published
Sep 1, 2026
Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu...
Critical
Unreviewed
CVE-2026-51764
was published
Sep 1, 2026
ProTip!
Advisories are also available from the
GraphQL API