GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
184 advisories
Filter by severity
MOOS essential-moos pAntler through 10.0.1 contains a remote code execution vulnerability that...
Critical
Unreviewed
CVE-2026-85427
was published
Sep 4, 2026
Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP...
Critical
Unreviewed
CVE-2026-82021
was published
Aug 28, 2026
The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN,...
High
Unreviewed
CVE-2026-59286
was published
Aug 27, 2026
An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and...
Critical
Unreviewed
CVE-2026-30612
was published
Aug 27, 2026
HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a...
Moderate
Unreviewed
CVE-2026-21810
was published
Aug 27, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker...
High
Unreviewed
CVE-2026-65097
was published
Aug 25, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker...
High
Unreviewed
CVE-2026-65081
was published
Aug 25, 2026
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction...
Critical
Unreviewed
CVE-2026-63310
was published
Aug 22, 2026
stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single...
High
Unreviewed
CVE-2026-76241
was published
Aug 19, 2026
atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)
High
GHSA-xhcr-cqfr-m3hv
was published
for
atomic-agents-stack
(pip)
Aug 17, 2026
ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the...
High
Unreviewed
CVE-2026-53970
was published
Aug 14, 2026
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading...
High
Unreviewed
CVE-2026-13433
was published
Aug 12, 2026
Duplicate Advisory: NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection
Moderate
GHSA-pv39-qrfq-g8gc
was published
for
nltk
(pip)
Aug 3, 2026
•
withdrawn
phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API...
Critical
Unreviewed
CVE-2026-66398
was published
Jul 27, 2026
pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
High
CVE-2026-55698
was published
for
pnpm
(npm)
Jun 26, 2026
pnpm: Repository-controlled configDependencies can select a pacquet native install engine
High
CVE-2026-55697
was published
for
pnpm
(npm)
Jun 26, 2026
Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version...
High
Unreviewed
CVE-2021-47987
was published
Jun 26, 2026
Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags...
High
Unreviewed
CVE-2021-47986
was published
Jun 26, 2026
Withdrawn Advisory: esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY
High
GHSA-gv7w-rqvm-qjhr
was published
for
esbuild
(npm)
Jun 12, 2026
•
withdrawn
stigmem-node's unsigned plugin override could be enabled without a second explicit acknowledgment
High
GHSA-w7pm-9g55-mxfm
was published
for
stigmem-node
(pip)
May 29, 2026
A firmware update mechanism in the affected charging controller fails to validate the...
Critical
Unreviewed
CVE-2026-9037
was published
May 28, 2026
The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained...
High
Unreviewed
CVE-2026-9089
was published
May 21, 2026
Electerm: Importing unsafe bookmark data could lead to unsafe operation when clicking local type bookmark
Critical
CVE-2026-45058
was published
for
electerm
(npm)
May 14, 2026
apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)
High
CVE-2026-42575
was published
for
chainguard.dev/apko
(Go)
May 4, 2026
Ollama for Windows does not perform integrity or authenticity verification of downloaded update...
High
Unreviewed
CVE-2026-42248
was published
Apr 29, 2026
ProTip!
Advisories are also available from the
GraphQL API