GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
50 advisories
Filter by severity
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An...
High
Unreviewed
CVE-2026-73266
was published
Aug 13, 2026
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor
High
CVE-2026-43910
was published
for
io.appium:java-client
(Maven)
Jul 28, 2026
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster...
High
Unreviewed
CVE-2026-17107
was published
Jul 24, 2026
An authenticated user with write privileges on a Queryable Encryption-enabled collection may be...
High
Unreviewed
CVE-2026-13062
was published
Jul 22, 2026
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode
High
CVE-2026-54628
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
High
CVE-2026-53514
was published
for
better-auth
(npm)
Jul 7, 2026
Apache Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation
High
CVE-2026-46592
was published
for
org.apache.camel:camel-cxf-rest
(Maven)
Jul 6, 2026
Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration
High
CVE-2026-49821
was published
for
github.com/fission/fission
(Go)
Jun 30, 2026
Strimzi: Cross-namespace privilege escalation via `Kafka.spec.entityOperator`
High
CVE-2026-55225
was published
for
io.strimzi:strimzi
(Maven)
Jun 18, 2026
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
High
CVE-2026-53999
was published
for
github.com/radius-project/radius
(Go)
Jun 12, 2026
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to...
High
Unreviewed
CVE-2026-36608
was published
Jun 3, 2026
In getCallingPackageName of Shared.java, there is a possible way to bypass activity start...
High
Unreviewed
CVE-2026-0098
was published
Jun 2, 2026
In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity...
High
Unreviewed
CVE-2025-48570
was published
Jun 2, 2026
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
High
CVE-2026-44494
was published
for
axios
(npm)
May 29, 2026
Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
High
CVE-2026-42043
was published
for
axios
(npm)
May 5, 2026
pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy via unrestricted `proxy.*` config (incomplete fix for CVE-2026-33509 / -35463 / -35464 / -35586)
High
CVE-2026-42313
was published
for
pyload-ng
(pip)
May 4, 2026
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET...
High
Unreviewed
CVE-2026-39906
was published
Apr 15, 2026
kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token
High
CVE-2026-40868
was published
for
github.com/kyverno/kyverno
(Go)
Apr 14, 2026
FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities
High
CVE-2026-27124
was published
for
fastmcp
(pip)
Mar 31, 2026
In gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c, there is a possible escalation of privileges due...
High
Unreviewed
CVE-2026-0107
was published
Mar 10, 2026
In multiple locations, there is a possible privilege escalation due to a confused deputy. This...
High
Unreviewed
CVE-2026-0008
was published
Mar 2, 2026
In setupLayout of PickActivity.java, there is a possible way to start any activity as a...
High
Unreviewed
CVE-2026-0013
was published
Mar 2, 2026
In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible cross-user...
High
Unreviewed
CVE-2026-0021
was published
Mar 2, 2026
In executeRequest of ActivityStarter.java, there is a possible launch anywhere due to a confused...
High
Unreviewed
CVE-2025-48646
was published
Mar 2, 2026
In multiple functions of MediaProvider.java, there is a possible external storage write...
High
Unreviewed
CVE-2025-48579
was published
Mar 2, 2026
ProTip!
Advisories are also available from the
GraphQL API