GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
759 advisories
Filter by severity
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and...
High
Unreviewed
CVE-2026-80112
was published
Sep 4, 2026
Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to...
High
Unreviewed
CVE-2026-78604
was published
Sep 2, 2026
Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory...
High
Unreviewed
CVE-2026-14208
was published
Aug 21, 2026
Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability...
High
Unreviewed
CVE-2026-18270
was published
Aug 20, 2026
In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify...
High
Unreviewed
CVE-2026-76399
was published
Aug 20, 2026
In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk...
High
Unreviewed
CVE-2026-76388
was published
Aug 20, 2026
A security vulnerability has been identified in Planet9 due to incorrect file permissions...
High
Unreviewed
CVE-2026-50602
was published
Aug 17, 2026
A maliciously created executable, when executed on the victim's machine, may allow a local low...
High
Unreviewed
CVE-2026-14478
was published
Aug 12, 2026
Incorrect directory permissions could allow a local user to escalate their privileges,...
High
Unreviewed
CVE-2025-0046
was published
Aug 11, 2026
Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized...
High
Unreviewed
CVE-2026-63522
was published
Aug 11, 2026
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The...
High
Unreviewed
CVE-2026-69108
was published
Aug 11, 2026
A VAPIX API parameter had improper input validation which could allow code execution and...
High
Unreviewed
CVE-2026-4757
was published
Aug 11, 2026
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption
High
CVE-2026-50570
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
High
Unreviewed
CVE-2026-61892
was published
Jul 25, 2026
Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to...
High
Unreviewed
CVE-2026-16157
was published
Jul 22, 2026
FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes...
High
Unreviewed
CVE-2026-63358
was published
Jul 21, 2026
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
High
CVE-2026-58424
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
High
CVE-2026-54447
was published
for
garminconnect
(pip)
Jul 15, 2026
OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in...
High
Unreviewed
CVE-2026-62194
was published
Jul 14, 2026
OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the...
High
Unreviewed
CVE-2026-62195
was published
Jul 14, 2026
mkfifo: permissions of an existing file are changed after FIFO creation fails
High
CVE-2026-35341
was published
for
uu_mkfifo
(Rust)
Jul 6, 2026
A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for...
High
Unreviewed
CVE-2026-13079
was published
Jul 3, 2026
Kahi has privilege-drop and socket/log permission issues
High
GHSA-55f6-4pr5-c7m5
was published
for
github.com/kahiteam/kahi
(Go)
Jun 30, 2026
This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2,...
High
Unreviewed
CVE-2026-43721
was published
Jun 29, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host
High
CVE-2026-49340
was published
for
go.senan.xyz/gonic
(Go)
Jun 26, 2026
ProTip!
Advisories are also available from the
GraphQL API