GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,584 advisories
Filter by severity
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and...
High
Unreviewed
CVE-2026-80112
was published
Sep 4, 2026
An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password...
Moderate
Unreviewed
CVE-2021-43613
was published
Sep 3, 2026
Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to...
High
Unreviewed
CVE-2026-78604
was published
Sep 2, 2026
Kimai before 2.63.0 contains an improper authorization vulnerability in team access endpoints...
Moderate
Unreviewed
CVE-2026-84806
was published
Sep 2, 2026
A security vulnerability has been detected in sambitraj Student-Management-System up to...
Low
Unreviewed
CVE-2026-82697
was published
Aug 31, 2026
PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its...
Low
Unreviewed
CVE-2026-59292
was published
Aug 27, 2026
rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode...
Low
Unreviewed
CVE-2026-79783
was published
Aug 25, 2026
Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory...
High
Unreviewed
CVE-2026-14208
was published
Aug 21, 2026
A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect...
Critical
Unreviewed
CVE-2026-66785
was published
Aug 20, 2026
Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability...
High
Unreviewed
CVE-2026-18270
was published
Aug 20, 2026
In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify...
High
Unreviewed
CVE-2026-76399
was published
Aug 20, 2026
In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk...
High
Unreviewed
CVE-2026-76388
was published
Aug 20, 2026
In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks...
Low
Unreviewed
CVE-2026-76371
was published
Aug 20, 2026
In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run...
Moderate
Unreviewed
CVE-2026-76372
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role...
Moderate
Unreviewed
CVE-2026-76260
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway...
Moderate
Unreviewed
CVE-2026-76261
was published
Aug 20, 2026
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
Critical
GHSA-m5w8-4gq2-6f8x
was published
for
vm2
(npm)
Aug 17, 2026
A security vulnerability has been identified in Planet9 due to incorrect file permissions...
High
Unreviewed
CVE-2026-50602
was published
Aug 17, 2026
A maliciously created executable, when executed on the victim's machine, may allow a local low...
High
Unreviewed
CVE-2026-14478
was published
Aug 12, 2026
Incorrect directory permissions could allow a local user to escalate their privileges,...
High
Unreviewed
CVE-2025-0046
was published
Aug 11, 2026
Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized...
High
Unreviewed
CVE-2026-63522
was published
Aug 11, 2026
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The...
High
Unreviewed
CVE-2026-69108
was published
Aug 11, 2026
A VAPIX API parameter had improper input validation which could allow code execution and...
High
Unreviewed
CVE-2026-4757
was published
Aug 11, 2026
A flaw was found in libvirt. During storage volume clone or convert operations, newly created...
Moderate
Unreviewed
CVE-2026-63623
was published
Aug 10, 2026
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
Low
GHSA-945v-v9p3-v5xw
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
ProTip!
Advisories are also available from the
GraphQL API