GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
536 advisories
Filter by severity
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
Moderate
CVE-2026-73555
was published
for
vllm
(pip)
Sep 4, 2026
CKAN MCP Server: Information disclosure via verbose error reflection
Low
CVE-2026-73844
was published
for
@aborruso/ckan-mcp-server
(npm)
Sep 3, 2026
An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns...
Moderate
Unreviewed
CVE-2026-11873
was published
Sep 1, 2026
A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive...
High
Unreviewed
CVE-2026-47893
was published
Aug 27, 2026
When the RabbitMQ management aliveness check fails, the configured admin password is embedded in...
Moderate
Unreviewed
CVE-2026-59271
was published
Aug 27, 2026
HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly...
Low
Unreviewed
CVE-2026-21809
was published
Aug 27, 2026
rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur....
Moderate
Unreviewed
CVE-2026-79777
was published
Aug 25, 2026
The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC...
Moderate
Unreviewed
CVE-2026-8173
was published
Aug 24, 2026
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
High
GHSA-ghvf-qf6h-g8x5
was published
for
@nocobase/server
(npm)
Aug 20, 2026
n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability...
High
Unreviewed
CVE-2026-77076
was published
Aug 20, 2026
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
Moderate
GHSA-hjwh-xvfw-qrwj
was published
for
mcp-searxng
(npm)
Aug 19, 2026
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling
Moderate
GHSA-92hr-gmr6-h8cp
was published
for
ep_etherpad-lite
(npm)
Aug 17, 2026
openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the ...
High
Unreviewed
CVE-2026-74879
was published
Aug 17, 2026
hashi-vault-js: Vault token and secret values exposed in thrown errors
Moderate
CVE-2026-55102
was published
for
hashi-vault-js
(npm)
Aug 13, 2026
HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions...
Moderate
Unreviewed
CVE-2026-56620
was published
Aug 10, 2026
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
Low
GHSA-gwfq-86j8-7qhv
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of...
Moderate
Unreviewed
CVE-2026-47622
was published
Aug 4, 2026
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
High
CVE-2026-69247
was published
for
cryptography
(pip)
Aug 3, 2026
HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory,...
Low
Unreviewed
CVE-2026-56571
was published
Jul 31, 2026
HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages...
Low
Unreviewed
CVE-2026-56568
was published
Jul 31, 2026
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9...
Moderate
Unreviewed
CVE-2026-11904
was published
Jul 30, 2026
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in...
Moderate
Unreviewed
CVE-2025-59177
was published
Jul 27, 2026
HCL Connections is vulnerable to information disclosure which could allow a user to obtain...
Low
Unreviewed
CVE-2026-56537
was published
Jul 27, 2026
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
High
CVE-2026-73409
was published
for
@budibase/server
(npm)
Jul 24, 2026
Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL...
Moderate
Unreviewed
CVE-2026-66009
was published
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API