GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
131 advisories
Filter by severity
A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect...
Critical
Unreviewed
CVE-2026-66785
was published
Aug 20, 2026
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
Critical
GHSA-m5w8-4gq2-6f8x
was published
for
vm2
(npm)
Aug 17, 2026
Decompress: Archive extraction can create files and links outside of the target directory
Critical
CVE-2026-53486
was published
for
@xhmikosr/decompress
(npm)
Jul 6, 2026
A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding...
Critical
Unreviewed
CVE-2026-10840
was published
Jun 4, 2026
Broadcast events allow malicious software to rewrite the device's default Mobile Device...
Critical
Unreviewed
CVE-2026-50209
was published
Jun 4, 2026
Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through...
Critical
Unreviewed
CVE-2026-9508
was published
May 29, 2026
Electerm Local code through electerm's single-instance socket
Critical
CVE-2026-45353
was published
for
electerm
(npm)
May 14, 2026
Pyroscope Exposes Storage Secret
Critical
CVE-2025-41118
was published
for
github.com/grafana/pyroscope
(Go)
Apr 15, 2026
File Browser's TUS Delete Endpoint Bypasses Delete Permission Check
Critical
CVE-2026-29188
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 4, 2026
An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly...
Critical
Unreviewed
CVE-2026-21902
was published
Feb 25, 2026
A security issue has been identified in ibaPDA that could allow unauthorized actions on the file...
Critical
Unreviewed
CVE-2025-14988
was published
Jan 27, 2026
The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded...
Critical
Unreviewed
CVE-2025-69426
was published
Jan 9, 2026
Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation...
Critical
Unreviewed
CVE-2025-12004
was published
Oct 21, 2025
Wondershare Repairit Incorrect Permission Assignment Authentication Bypass Vulnerability. This...
Critical
Unreviewed
CVE-2025-10643
was published
Sep 17, 2025
A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions...
Critical
Unreviewed
CVE-2025-40804
was published
Sep 9, 2025
The configuration file containing database logins and passwords is readable by any local user.
Critical
Unreviewed
CVE-2025-30063
was published
Aug 27, 2025
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior...
Critical
Unreviewed
CVE-2025-4609
was published
Aug 22, 2025
Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start...
Critical
Unreviewed
CVE-2025-8042
was published
Aug 19, 2025
LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows...
Critical
Unreviewed
CVE-2025-46093
was published
Aug 5, 2025
Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view...
Critical
Unreviewed
CVE-2025-45150
was published
Aug 1, 2025
Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a...
Critical
Unreviewed
CVE-2014-125121
was published
Jul 31, 2025
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Critical
Unreviewed
CVE-2025-43243
was published
Jul 30, 2025
An incorrect default permissions vulnerability exists in the CServerSettings::SetRegistryValues...
Critical
Unreviewed
CVE-2025-26469
was published
Jul 28, 2025
The Marathon UI in DC/OS < 1.9.0 allows unauthenticated users to deploy arbitrary Docker...
Critical
Unreviewed
CVE-2017-20198
was published
Jul 23, 2025
The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions,...
Critical
Unreviewed
CVE-2025-25373
was published
Mar 25, 2025
ProTip!
Advisories are also available from the
GraphQL API