GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
23 advisories
Filter by severity
In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the...
Moderate
Unreviewed
CVE-2026-81684
was published
Aug 27, 2026
A flaw was found in the ipa_getkeytab module of the community.general
Ansible collection. The...
Moderate
Unreviewed
CVE-2026-80158
was published
Aug 27, 2026
NVIDIA NemoClaw contains a vulnerability where an attacker could cause
invocation of process...
Moderate
Unreviewed
CVE-2026-65088
was published
Aug 25, 2026
Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17...
High
Unreviewed
CVE-2026-76054
was published
Aug 24, 2026
openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in...
High
Unreviewed
CVE-2026-74873
was published
Aug 17, 2026
Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM...
Moderate
Unreviewed
CVE-2026-18915
was published
Aug 6, 2026
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
High
GHSA-94p4-4cq8-9g67
was published
for
GitPython
(pip)
Jul 24, 2026
Tanium addressed an information disclosure vulnerability in Connect.
Moderate
Unreviewed
CVE-2026-12139
was published
Jul 21, 2026
An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu...
Moderate
Unreviewed
CVE-2026-9494
was published
Jul 16, 2026
Invocation of process using visible sensitive information vulnerability in TUBITAK BILGEM...
High
Unreviewed
CVE-2026-12250
was published
Jul 5, 2026
OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based...
Low
Unreviewed
CVE-2026-41357
was published
Apr 24, 2026
PraisonAI Vulnerable to Sensitive Environment Variable Exposure via Untrusted MCP Subprocess Execution
Moderate
CVE-2026-40159
was published
for
PraisonAI
(pip)
Apr 10, 2026
A malicious ACAP application can gain access to admin-level service account credentials used by...
Moderate
Unreviewed
CVE-2025-5452
was published
Nov 11, 2025
A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker...
Moderate
Unreviewed
CVE-2025-53860
was published
Oct 15, 2025
An issue was discovered in BMC Control-M 9.0.21.300. When Control-M Server has a database...
Critical
Unreviewed
CVE-2025-48709
was published
Aug 7, 2025
IBM MQ Container when used with the IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0...
Moderate
Unreviewed
CVE-2025-1333
was published
May 2, 2025
Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used,...
Moderate
Unreviewed
CVE-2025-32987
was published
Apr 15, 2025
IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0...
Moderate
Unreviewed
CVE-2024-28799
was published
Aug 14, 2024
The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main'...
High
Unreviewed
CVE-2024-4254
was published
Jun 4, 2024
Invocation of the sqlplus command with sensitive information in the command line in the mk_oracle...
Low
Unreviewed
CVE-2024-1742
was published
Mar 22, 2024
CloudLinux
CageFS 7.1.1-1 or below passes the authentication token as command line
argument. In...
High
Unreviewed
CVE-2020-36771
was published
Jan 22, 2024
Veracode Scan Jenkins Plugin vulnerable to information disclosure
Moderate
CVE-2023-25722
was published
for
com.veracode.jenkins:veracode-scan
(Maven)
Mar 28, 2023
Undertow vulnerable to Denial of Service (DoS) attacks
High
CVE-2021-3859
was published
for
io.undertow:undertow-core
(Maven)
Jul 15, 2022
ProTip!
Advisories are also available from the
GraphQL API