GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
373 advisories
Filter by severity
XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control...
High
Unreviewed
CVE-2026-66840
was published
Sep 4, 2026
Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.
High
Unreviewed
CVE-2026-81774
was published
Sep 2, 2026
Kirby: System path exposure from error messages in the REST API
Moderate
CVE-2026-69127
was published
for
getkirby/cms
(Composer)
Sep 1, 2026
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat...
High
Unreviewed
CVE-2026-78268
was published
Aug 25, 2026
The Brushfire platform's video content streaming application (https://online.brushfire.com)...
Moderate
Unreviewed
CVE-2026-75928
was published
Aug 21, 2026
Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System...
Moderate
Unreviewed
CVE-2026-67267
was published
Aug 19, 2026
Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image...
Moderate
Unreviewed
CVE-2026-74007
was published
Aug 18, 2026
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
High
Unreviewed
CVE-2026-32468
was published
Aug 18, 2026
OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals...
High
Unreviewed
CVE-2024-58375
was published
Aug 16, 2026
Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.
Moderate
Unreviewed
CVE-2026-66444
was published
Aug 13, 2026
Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.
High
Unreviewed
CVE-2026-66462
was published
Aug 13, 2026
TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without...
Low
Unreviewed
CVE-2025-15680
was published
Aug 10, 2026
Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel...
Moderate
Unreviewed
CVE-2026-6373
was published
Aug 10, 2026
Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account...
Moderate
Unreviewed
CVE-2026-17595
was published
Aug 7, 2026
Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
Moderate
Unreviewed
CVE-2026-28169
was published
Aug 6, 2026
HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public...
Moderate
Unreviewed
CVE-2026-56569
was published
Jul 31, 2026
SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier...
Moderate
Unreviewed
CVE-2026-58246
was published
Jul 28, 2026
Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.
Moderate
Unreviewed
CVE-2026-65564
was published
Jul 27, 2026
Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.
Moderate
Unreviewed
CVE-2026-66438
was published
Jul 27, 2026
Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.
High
Unreviewed
CVE-2026-59548
was published
Jul 27, 2026
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
High
Unreviewed
CVE-2026-59528
was published
Jul 27, 2026
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive...
Moderate
Unreviewed
CVE-2025-59178
was published
Jul 27, 2026
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information...
Moderate
Unreviewed
CVE-2026-44955
was published
Jul 24, 2026
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information...
Critical
Unreviewed
CVE-2026-28698
was published
Jul 24, 2026
Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
Moderate
Unreviewed
CVE-2026-65535
was published
Jul 23, 2026
ProTip!
Advisories are also available from the
GraphQL API