GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,340
Maven
5,000+
npm
5,000+
NuGet
1,033
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
27,418 advisories
Filter by severity
Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin...
Critical
Unreviewed
CVE-2026-62232
was published
Jul 17, 2026
The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,...
Critical
Unreviewed
CVE-2026-14956
was published
Jul 17, 2026
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and...
Critical
Unreviewed
CVE-2026-53412
was published
Jul 17, 2026
YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup...
Critical
Unreviewed
CVE-2026-57075
was published
Jul 17, 2026
WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one...
Critical
Unreviewed
CVE-2026-63089
was published
Jul 16, 2026
A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9...
Critical
Unreviewed
CVE-2026-38158
was published
Jul 16, 2026
The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately...
Critical
Unreviewed
CVE-2026-15422
was published
Jul 16, 2026
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows...
Critical
Unreviewed
CVE-2026-63087
was published
Jul 16, 2026
XML::Bare versions through 0.53 for Perl have an unbounded character lookahead.
The...
Critical
Unreviewed
CVE-2026-57074
was published
Jul 16, 2026
HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead.
The...
Critical
Unreviewed
CVE-2026-57073
was published
Jul 16, 2026
Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library.
...
Critical
Unreviewed
CVE-2026-3031
was published
Jul 16, 2026
SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable...
Critical
Unreviewed
CVE-2026-14890
was published
Jul 16, 2026
An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly...
Critical
Unreviewed
CVE-2026-11386
was published
Jul 16, 2026
AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php...
Critical
Unreviewed
CVE-2026-63305
was published
Jul 16, 2026
stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in...
Critical
Unreviewed
CVE-2026-63306
was published
Jul 16, 2026
AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone...
Critical
Unreviewed
CVE-2026-63304
was published
Jul 16, 2026
Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization...
Critical
Unreviewed
CVE-2026-22752
was published
Jul 16, 2026
An unauthenticated remote attacker can execute any command on the affected device due to not...
Critical
Unreviewed
CVE-2023-49899
was published
Jul 16, 2026
An unauthenticated remote attacker is able to perform remote code execution due to incorrectly...
Critical
Unreviewed
CVE-2023-49900
was published
Jul 16, 2026
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 may...
Critical
Unreviewed
CVE-2026-15925
was published
Jul 16, 2026
The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one...
Critical
Unreviewed
CVE-2026-12492
was published
Jul 16, 2026
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass...
Critical
Unreviewed
CVE-2026-15013
was published
Jul 16, 2026
A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3...
Critical
Unreviewed
CVE-2026-26718
was published
Jul 16, 2026
xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server...
Critical
Unreviewed
CVE-2026-30618
was published
Jul 16, 2026
LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation...
Critical
Unreviewed
CVE-2026-30623
was published
Jul 16, 2026
ProTip!
Advisories are also available from the
GraphQL API