GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
45 advisories
Filter by severity
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits
High
CVE-2026-55763
was published
for
github.com/klever-io/klever-go
(Go)
Aug 28, 2026
WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The...
Moderate
Unreviewed
CVE-2026-78103
was published
Aug 28, 2026
A pop-up logic flaw in a certain feature of Kids Mode allows users to bypass password...
Low
Unreviewed
CVE-2026-15365
was published
Aug 26, 2026
Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team...
High
Unreviewed
CVE-2026-80195
was published
Aug 26, 2026
Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65...
High
Unreviewed
CVE-2026-79083
was published
Aug 25, 2026
Our payment integration with GiroCheckout did not properly validate
payment status responses. An...
Moderate
Unreviewed
CVE-2026-18029
was published
Jul 28, 2026
A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix...
Moderate
Unreviewed
CVE-2026-16103
was published
Jul 17, 2026
Sylius: Cart FormComponent allows modification or deletion of an already-completed order
Moderate
CVE-2026-53637
was published
for
sylius/sylius
(Composer)
Jul 9, 2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to...
Moderate
Unreviewed
CVE-2025-36333
was published
Jun 30, 2026
Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission
High
CVE-2026-48505
was published
for
filament/filament
(Composer)
Jun 25, 2026
Our payment integration with Computop-based payment methods did not
properly validate payment...
Moderate
Unreviewed
CVE-2026-13223
was published
Jun 25, 2026
Our payment integration with Oppwa-based payment methods did not
properly validate payment...
Moderate
Unreviewed
CVE-2026-13222
was published
Jun 25, 2026
Our payment integration with Mollie did not properly validate payment
status responses. An...
Moderate
Unreviewed
CVE-2026-57536
was published
Jun 25, 2026
gun has an Unexpected Status Code or Return Value vulnerability
High
CVE-2026-43974
was published
for
gun
(Erlang)
Jun 8, 2026
Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature...
Low
Unreviewed
CVE-2026-8477
was published
May 26, 2026
Ethyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection
Moderate
CVE-2026-42303
was published
for
ethyca-fides
(pip)
May 5, 2026
YAFNET: Pre-Handler Authorization Bypass on Admin Pages Enables Blind SQL Execution via `/Admin/RunSql`
High
CVE-2026-43937
was published
for
YAFNET.Core
(NuGet)
May 5, 2026
net-imap vulnerable to STARTTLS stripping via invalid response timing
High
CVE-2026-42246
was published
for
net-imap
(RubyGems)
May 4, 2026
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in...
High
Unreviewed
CVE-2026-30574
was published
Mar 27, 2026
IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service...
Low
Unreviewed
CVE-2025-13459
was published
Mar 16, 2026
Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an...
Critical
Unreviewed
CVE-2026-3130
was published
Mar 4, 2026
Improper Enforcement of Behavioral Workflow vulnerability in Seneka Software Hardware Information...
Low
Unreviewed
CVE-2025-13129
was published
Dec 1, 2025
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker...
Moderate
Unreviewed
CVE-2025-55682
was published
Oct 14, 2025
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker...
Moderate
Unreviewed
CVE-2025-55330
was published
Oct 14, 2025
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker...
Moderate
Unreviewed
CVE-2025-55332
was published
Oct 14, 2025
ProTip!
Advisories are also available from the
GraphQL API