GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
754 advisories
Filter by severity
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized...
Critical
Unreviewed
CVE-2026-80098
was published
Sep 4, 2026
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization,...
Critical
Unreviewed
CVE-2026-85394
was published
Sep 3, 2026
node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences...
High
Unreviewed
CVE-2026-85393
was published
Sep 3, 2026
A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3)...
High
Unreviewed
CVE-2026-80465
was published
Sep 3, 2026
A signature verification bypass vulnerability exists in the command line interface of AOS-CX....
High
Unreviewed
CVE-2026-73776
was published
Sep 1, 2026
Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded...
Critical
Unreviewed
CVE-2026-82876
was published
Aug 31, 2026
AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live...
Critical
Unreviewed
CVE-2026-82645
was published
Aug 30, 2026
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry...
High
Unreviewed
CVE-2026-82461
was published
Aug 29, 2026
The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication...
Critical
Unreviewed
CVE-2026-82454
was published
Aug 29, 2026
AIIR verification and policy gates could report success without enforcing the control (fail-open)
Moderate
GHSA-73p9-6hrp-8qhr
was published
for
aiir
(pip)
Aug 28, 2026
Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel)
High
CVE-2026-54736
was published
for
phalcon/cphalcon
(Composer)
Aug 28, 2026
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all...
Critical
Unreviewed
CVE-2026-76581
was published
Aug 28, 2026
openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching...
Critical
Unreviewed
CVE-2026-81714
was published
Aug 27, 2026
openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the...
Critical
Unreviewed
CVE-2026-81717
was published
Aug 27, 2026
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in...
Critical
Unreviewed
CVE-2026-81700
was published
Aug 27, 2026
openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins,...
Critical
Unreviewed
CVE-2026-81701
was published
Aug 27, 2026
openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope...
Critical
Unreviewed
CVE-2026-81680
was published
Aug 27, 2026
A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior...
High
Unreviewed
CVE-2026-75946
was published
Aug 21, 2026
Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0...
High
Unreviewed
CVE-2026-68745
was published
Aug 21, 2026
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized...
Critical
Unreviewed
CVE-2026-62834
was published
Aug 21, 2026
The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an...
Moderate
Unreviewed
CVE-2026-72861
was published
Aug 20, 2026
node-opcua missing nonce verification in UserNameIdentityToken authentication
High
CVE-2026-54155
was published
for
node-opcua
(npm)
Aug 20, 2026
Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4...
Critical
Unreviewed
CVE-2026-19505
was published
Aug 19, 2026
libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain...
High
Unreviewed
CVE-2026-76234
was published
Aug 19, 2026
The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of...
Moderate
Unreviewed
CVE-2026-50720
was published
Aug 19, 2026
ProTip!
Advisories are also available from the
GraphQL API