GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
72 advisories
Filter by severity
Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
Moderate
CVE-2026-58191
was published
for
@appium/base-driver
(npm)
Sep 1, 2026
A malicious actor with access to the network, low privileges and under certain conditions could...
Critical
Unreviewed
CVE-2026-77545
was published
Aug 27, 2026
A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for...
High
Unreviewed
CVE-2026-66787
was published
Aug 20, 2026
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be...
High
Unreviewed
CVE-2026-66405
was published
Aug 10, 2026
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor...
High
Unreviewed
CVE-2026-66403
was published
Aug 10, 2026
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in...
High
Unreviewed
CVE-2026-65893
was published
Jul 27, 2026
Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker...
High
Unreviewed
CVE-2026-58378
was published
Jul 9, 2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions <...
High
Unreviewed
CVE-2026-54799
was published
Jul 9, 2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions <...
High
Unreviewed
CVE-2026-54798
was published
Jul 9, 2026
JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability...
High
Unreviewed
CVE-2026-59092
was published
Jul 2, 2026
fixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8`
Low
GHSA-fq3w-p4fg-mw73
was published
for
fixurjavainstall
(Rust)
Jun 25, 2026
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(...
High
Unreviewed
CVE-2026-49188
was published
Jun 4, 2026
stigmem-node's federation insecure transport settings may allow non-loopback cleartext federation
Critical
GHSA-jmfc-hfjq-pxcp
was published
for
stigmem-node
(pip)
May 29, 2026
Algernon: Single-file mode unconditionally enables debug mode
High
CVE-2026-45728
was published
for
github.com/xyproto/algernon
(Go)
May 19, 2026
Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that...
Critical
Unreviewed
CVE-2026-40035
was published
Apr 9, 2026
Development and test API endpoints are present that mirror production functionality.
Moderate
Unreviewed
CVE-2026-32662
was published
Apr 3, 2026
Digital Photo Frame GH-WDF10A provided by GREEN HOUSE CO., LTD. contains an active debug code...
High
Unreviewed
CVE-2026-33201
was published
Mar 26, 2026
Sprig Plugin for Craft CMS potentially discloses sensitive information via Sprig Playground
Moderate
CVE-2026-27131
was published
for
putyourlightson/craft-sprig
(Composer)
Mar 23, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
GHSA-vg9h-jx4v-cwx2
was published
for
dfir-unfurl
(pip)
Jan 29, 2026
A vulnerability exists in serial device servers where active debug code remains enabled in the...
High
Unreviewed
CVE-2025-15017
was published
Dec 31, 2025
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an...
Moderate
Unreviewed
CVE-2025-42872
was published
Dec 9, 2025
The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in...
Low
Unreviewed
CVE-2025-2486
was published
Nov 26, 2025
Smart Video Doorbell firmware versions prior to 2.01.078 contain an active debug code...
High
Unreviewed
CVE-2025-64983
was published
Nov 26, 2025
An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3,...
Moderate
Unreviewed
CVE-2025-54660
was published
Nov 18, 2025
Active debug code for some Intel UEFI reference platforms within Ring 0: Kernel may allow a...
High
Unreviewed
CVE-2025-30185
was published
Nov 11, 2025
ProTip!
Advisories are also available from the
GraphQL API