GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,606
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,831
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
1,119 advisories
Filter by severity
Tanium addressed an information disclosure vulnerability in Threat Response.
Low
Unreviewed
CVE-2026-6392
was published
Apr 22, 2026
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...
Low
Unreviewed
CVE-2026-34268
was published
Apr 21, 2026
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...
Low
Unreviewed
CVE-2026-22007
was published
Apr 21, 2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema)...
Low
Unreviewed
CVE-2026-22001
was published
Apr 21, 2026
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are...
Low
Unreviewed
CVE-2026-22051
was published
Apr 21, 2026
In Grafana's alerting system, users with edit permissions for a contact point, specifically the...
Low
Unreviewed
CVE-2025-12141
was published
Apr 15, 2026
Craft Commerce has an unauthenticated information disclosure that can leak some customer order data on anonymous payments
Low
CVE-2026-32270
was published
for
craftcms/commerce
(Composer)
Apr 14, 2026
A vulnerability was found in code-projects Online Library Management System 1.0. Affected is an...
Low
Unreviewed
CVE-2026-6000
was published
Apr 10, 2026
Wasmtime has host data leakage with 64-bit tables and Winch
Low
CVE-2026-34945
was published
for
wasmtime
(Rust)
Apr 9, 2026
A weakness has been identified in code-projects Patient Record Management System 1.0. This...
Low
Unreviewed
CVE-2026-5960
was published
Apr 9, 2026
A vulnerability has been found in code-projects Movie Ticketing System 1.0. Impacted is an...
Low
Unreviewed
CVE-2026-5847
was published
Apr 9, 2026
An issue that could allow a user with access to a credential to view sensitive fields through an...
Low
Unreviewed
CVE-2026-5375
was published
Apr 7, 2026
Signal K Server: Arbitrary Prototype Read via `from` Field Bypass
Low
CVE-2026-35038
was published
for
signalk-server
(npm)
Apr 3, 2026
Nhost Leaks Refresh Tokens via URL Query Parameter in OAuth Provider Callback
Low
CVE-2026-34969
was published
for
github.com/nhost/nhost
(Go)
Apr 1, 2026
AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect
Low
CVE-2026-34518
was published
for
aiohttp
(pip)
Apr 1, 2026
Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata
Low
GHSA-44px-qjjc-xrhq
was published
for
craftcms/cms
(Composer)
Mar 26, 2026
HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights...
Low
Unreviewed
CVE-2025-55272
was published
Mar 26, 2026
HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a...
Low
Unreviewed
CVE-2025-55276
was published
Mar 26, 2026
A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this...
Low
Unreviewed
CVE-2026-4823
was published
Mar 26, 2026
Craft CMS' anonymous "assets/image-editor" calls return private asset editor metadata to unauthorized users
Low
CVE-2026-33161
was published
for
craftcms/cms
(Composer)
Mar 24, 2026
Broken Access Control in extension "Redirect Tab" (redirect_tab)
Low
CVE-2026-4202
was published
for
ayacoo/redirect-tab
(Composer)
Mar 17, 2026
Google Cloud Storage for Craft CMS has an Information Disclosure Vulnerability
Low
CVE-2026-32266
was published
for
craftcms/google-cloud
(Composer)
Mar 16, 2026
HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature....
Low
Unreviewed
CVE-2025-52649
was published
Mar 16, 2026
A vulnerability was detected in myAEDES App up to 1.18.4 on Android. Affected is an unknown...
Low
Unreviewed
CVE-2026-4218
was published
Mar 16, 2026
Withdrawn Advisory: Shescape has possible misidentification of shell due to link chains
Low
CVE-2026-30916
was published
for
shescape
(npm)
Mar 7, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API