GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,417 advisories
Filter by severity
SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
Low
GHSA-6hxq-p678-4hr2
was published
for
@simplewebauthn/server
(npm)
Sep 4, 2026
Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed...
High
Unreviewed
CVE-2026-85525
was published
Sep 4, 2026
Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share...
Moderate
Unreviewed
CVE-2026-15937
was published
Sep 4, 2026
IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates...
Moderate
Unreviewed
CVE-2026-9036
was published
Sep 3, 2026
In the current development version of Eclipse aeriOS, for which no official release has yet been...
High
Unreviewed
CVE-2026-84736
was published
Sep 3, 2026
MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient:...
High
Unreviewed
CVE-2026-85221
was published
Sep 3, 2026
In the current development version of Eclipse aeriOS, which has not yet had an official release,...
Critical
Unreviewed
CVE-2026-82955
was published
Sep 2, 2026
Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through...
High
Unreviewed
CVE-2026-82662
was published
Aug 31, 2026
Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned...
High
Unreviewed
CVE-2026-41012
was published
Aug 29, 2026
When mongosqld is configured with a client certificate authority file, the listener requests a...
High
Unreviewed
CVE-2026-81518
was published
Aug 29, 2026
IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions...
Moderate
Unreviewed
CVE-2025-64649
was published
Aug 29, 2026
IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly...
Moderate
Unreviewed
CVE-2025-36290
was published
Aug 29, 2026
MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`
High
CVE-2026-55215
was published
for
mariadb
(npm)
Aug 28, 2026
ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability,...
Critical
Unreviewed
CVE-2026-18717
was published
Aug 28, 2026
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation...
Moderate
Unreviewed
CVE-2026-74774
was published
Aug 26, 2026
Netmaker disables certificate verification on the connection to the configured mail server. The...
High
Unreviewed
CVE-2026-81034
was published
Aug 26, 2026
kas Persistently Disables SSH Host Key Checking
Low
CVE-2026-54548
was published
for
kas
(pip)
Aug 26, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker...
High
Unreviewed
CVE-2026-65084
was published
Aug 25, 2026
X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in...
High
Unreviewed
CVE-2026-79785
was published
Aug 25, 2026
A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS...
Moderate
Unreviewed
CVE-2026-78323
was published
Aug 24, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary...
High
Unreviewed
CVE-2026-17024
was published
Aug 21, 2026
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the...
High
Unreviewed
CVE-2026-76403
was published
Aug 20, 2026
In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network...
High
Unreviewed
CVE-2026-76362
was published
Aug 20, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the...
Critical
Unreviewed
CVE-2026-16822
was published
Aug 19, 2026
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80,...
Critical
Unreviewed
CVE-2026-16835
was published
Aug 19, 2026
ProTip!
Advisories are also available from the
GraphQL API