GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
148 advisories
Filter by severity
phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API...
Critical
Unreviewed
CVE-2026-66398
was published
Jul 27, 2026
Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version...
High
Unreviewed
CVE-2021-47987
was published
Jun 26, 2026
Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags...
High
Unreviewed
CVE-2021-47986
was published
Jun 26, 2026
A firmware update mechanism in the affected charging controller fails to validate the...
Critical
Unreviewed
CVE-2026-9037
was published
May 28, 2026
The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained...
High
Unreviewed
CVE-2026-9089
was published
May 21, 2026
Ollama for Windows does not perform integrity or authenticity verification of downloaded update...
High
Unreviewed
CVE-2026-42248
was published
Apr 29, 2026
Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The ...
High
Unreviewed
CVE-2026-40066
was published
Apr 17, 2026
TrueConf Client downloads application update code and applies it without performing verification....
High
Unreviewed
CVE-2026-3502
was published
Mar 30, 2026
An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver...
Moderate
Unreviewed
CVE-2026-1878
was published
Mar 12, 2026
IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability,...
Critical
Unreviewed
CVE-2026-3000
was published
Mar 2, 2026
IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability,...
Critical
Unreviewed
CVE-2026-2999
was published
Mar 2, 2026
Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows...
Moderate
Unreviewed
CVE-2025-47904
was published
Feb 24, 2026
MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution...
Critical
Unreviewed
CVE-2026-27180
was published
Feb 19, 2026
The firmware update functionality does not verify the authenticity of the supplied firmware...
Moderate
Unreviewed
CVE-2025-15575
was published
Feb 12, 2026
A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco...
Moderate
Unreviewed
CVE-2026-20056
was published
Feb 4, 2026
Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity...
High
Unreviewed
CVE-2025-15556
was published
Feb 3, 2026
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before...
High
Unreviewed
CVE-2025-55310
was published
Dec 11, 2025
In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within...
Critical
Unreviewed
CVE-2025-14265
was published
Dec 11, 2025
Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of...
Low
Unreviewed
CVE-2025-66332
was published
Dec 8, 2025
Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of...
Low
Unreviewed
CVE-2025-66331
was published
Dec 8, 2025
Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of...
Low
Unreviewed
CVE-2025-66334
was published
Dec 8, 2025
Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of...
Low
Unreviewed
CVE-2025-66333
was published
Dec 8, 2025
An issue in Shirt Pocket SuperDuper! V.3.10 and before allows a local attacker to execute...
High
Unreviewed
CVE-2025-61228
was published
Dec 1, 2025
The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure...
High
Unreviewed
CVE-2025-63434
was published
Nov 24, 2025
Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance...
Moderate
Unreviewed
CVE-2025-40604
was published
Nov 20, 2025
ProTip!
Advisories are also available from the
GraphQL API