GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,450
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,134
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
15,778 advisories
Filter by severity
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
Low
CVE-2026-55403
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape
Low
CVE-2026-50568
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
CVE-2026-54620
was published
for
sqlite3
(RubyGems)
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
CVE-2026-54619
was published
for
sqlite3
(RubyGems)
Jul 28, 2026
`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when...
Low
Unreviewed
CVE-2026-6879
was published
Jul 28, 2026
A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is...
Low
Unreviewed
CVE-2026-18038
was published
Jul 28, 2026
A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can...
Low
Unreviewed
CVE-2026-17072
was published
Jul 28, 2026
The "quick setup" view presented to users after they first create an
event allows to set up the...
Low
Unreviewed
CVE-2026-18028
was published
Jul 28, 2026
Successful exploitation of this vulnerability
could allow an attacker with local network access...
Low
Unreviewed
CVE-2026-55977
was published
Jul 28, 2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability...
Low
Unreviewed
CVE-2026-14821
was published
Jul 28, 2026
The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event...
Low
Unreviewed
CVE-2026-14819
was published
Jul 28, 2026
This issue was addressed with additional restrictions on the lock screen. This issue is fixed in...
Low
Unreviewed
CVE-2026-64745
was published
Jul 27, 2026
A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is...
Low
Unreviewed
CVE-2026-17531
was published
Jul 27, 2026
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this...
Low
Unreviewed
CVE-2026-17530
was published
Jul 27, 2026
A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown...
Low
Unreviewed
CVE-2026-17529
was published
Jul 27, 2026
A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this...
Low
Unreviewed
CVE-2026-17514
was published
Jul 27, 2026
A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function...
Low
Unreviewed
CVE-2026-17513
was published
Jul 27, 2026
A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function...
Low
Unreviewed
CVE-2026-17512
was published
Jul 27, 2026
HCL Connections is vulnerable to information disclosure which could allow a user to obtain...
Low
Unreviewed
CVE-2026-56537
was published
Jul 27, 2026
An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this...
Low
Unreviewed
CVE-2026-56538
was published
Jul 27, 2026
The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is...
Low
Unreviewed
CVE-2026-40000
was published
Jul 27, 2026
The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field...
Low
Unreviewed
CVE-2026-14189
was published
Jul 27, 2026
A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function...
Low
Unreviewed
CVE-2026-17458
was published
Jul 26, 2026
A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the...
Low
Unreviewed
CVE-2026-17459
was published
Jul 26, 2026
A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the...
Low
Unreviewed
CVE-2026-17457
was published
Jul 26, 2026
ProTip!
Advisories are also available from the
GraphQL API