GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,866
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,587
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,482 advisories
Filter by severity
PictShare before 3.7.1 contains an information disclosure vulnerability that allows...
High
Unreviewed
CVE-2026-104051
was published
Oct 2, 2026
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in...
High
Unreviewed
CVE-2026-103256
was published
Oct 1, 2026
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-92537
was published
Oct 1, 2026
In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by...
Low
Unreviewed
CVE-2026-100264
was published
Sep 30, 2026
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, two user‑information endpoints can reveal...
High
Unreviewed
CVE-2026-100298
was published
Sep 29, 2026
Apache Airflow's Snowflake provider did not validate the connection's `account` and `region`...
Moderate
Unreviewed
CVE-2026-81930
was published
Sep 29, 2026
Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile...
Low
Unreviewed
CVE-2026-101089
was published
Sep 27, 2026
OpenClaw is an npm-distributed application. In versions >= 2026.4.25 and < 2026.8.1, the...
Moderate
Unreviewed
CVE-2026-100569
was published
Sep 26, 2026
Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for...
Moderate
Unreviewed
CVE-2026-92680
was published
Sep 24, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive...
High
Unreviewed
CVE-2026-81208
was published
Sep 24, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to...
Moderate
Unreviewed
CVE-2026-18124
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to...
High
Unreviewed
CVE-2026-17643
was published
Sep 23, 2026
Insufficiently protected credentials in the host and folder configuration endpoints of the REST...
Moderate
Unreviewed
CVE-2026-92882
was published
Sep 22, 2026
Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()
High
CVE-2026-76839
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled
High
CVE-2026-76846
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target
Moderate
CVE-2026-85717
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request
Moderate
CVE-2026-85720
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient...
Moderate
Unreviewed
CVE-2026-89064
was published
Sep 17, 2026
SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the...
High
Unreviewed
CVE-2026-92759
was published
Sep 16, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco...
Critical
Unreviewed
CVE-2026-20234
was published
Sep 16, 2026
Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for...
Moderate
Unreviewed
CVE-2026-92133
was published
Sep 16, 2026
NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in...
High
Unreviewed
CVE-2026-92256
was published
Sep 16, 2026
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in...
High
Unreviewed
CVE-2026-76871
was published
Sep 16, 2026
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in...
High
Unreviewed
CVE-2026-76854
was published
Sep 16, 2026
Netcore NR255-V firmware version 1.5.130703 contains a sensitive information disclosure...
High
Unreviewed
CVE-2026-76857
was published
Sep 16, 2026
ProTip!
Advisories are also available from the
GraphQL API