GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,521
Maven
5,000+
npm
5,000+
NuGet
912
pip
4,768
Pub
13
RubyGems
1,036
Rust
1,229
Swift
53
Unreviewed advisories
All unreviewed
5,000+
12,024 advisories
Filter by severity
A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function...
Moderate
Unreviewed
CVE-2026-5536
was published
Apr 5, 2026
Directus: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in File Import
High
CVE-2026-35409
was published
for
directus
(npm)
Apr 4, 2026
Directus: Open Redirect via Parser Bypass in OAuth2/SAML Authentication Flow
Moderate
CVE-2026-35410
was published
for
directus
(npm)
Apr 4, 2026
Hirschmann HiOS devices versions prior to 08.1.00 and 07.1.01 contain a denial of service...
High
Unreviewed
CVE-2020-37216
was published
Apr 3, 2026
A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function...
Low
Unreviewed
CVE-2026-5473
was published
Apr 3, 2026
Signal K Server: Arbitrary Prototype Read via `from` Field Bypass
Low
CVE-2026-35038
was published
for
signalk-server
(npm)
Apr 3, 2026
Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
Moderate
CVE-2026-34773
was published
for
electron
(npm)
Apr 3, 2026
fast-jwt: Incomplete fix for CVE-2023-48223: JWT Algorithm Confusion via Whitespace-Prefixed RSA Public Key
Critical
CVE-2026-34950
was published
for
fast-jwt
(npm)
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject...
High
Unreviewed
CVE-2026-29141
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner...
High
Unreviewed
CVE-2026-29143
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject...
High
Unreviewed
CVE-2026-29144
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from...
Moderate
Unreviewed
CVE-2026-29137
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag...
Moderate
Unreviewed
CVE-2026-29135
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with...
Moderate
Unreviewed
CVE-2026-29133
was published
Apr 2, 2026
Ella Core Has Audit Log Falsification via Path/Body IMSI Mismatch in UpdateSubscriber
Low
CVE-2026-34762
was published
for
github.com/ellanetworks/core
(Go)
Apr 1, 2026
AIOHTTP accepts duplicate Host headers
Moderate
CVE-2026-34525
was published
for
aiohttp
(pip)
Apr 1, 2026
ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
High
CVE-2026-34445
was published
for
onnx
(pip)
Apr 1, 2026
A vulnerability in the change password functionality of Cisco Integrated Management Controller ...
Critical
Unreviewed
CVE-2026-20093
was published
Apr 1, 2026
A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the...
Moderate
Unreviewed
CVE-2026-30523
was published
Apr 1, 2026
openssl-encrypt silently skips schema validation when jsonschema library is not installed
Moderate
GHSA-425g-fjhq-5h92
was published
for
openssl-encrypt
(pip)
Mar 31, 2026
Admidio has CSRF and Form Validation Bypass in Inventory Item Save via `imported` Parameter
Moderate
CVE-2026-34383
was published
for
admidio/admidio
(Composer)
Mar 31, 2026
phpMyFAQ is Vulnerable to Stored XSS via Unsanitized Email Field in Admin FAQ Editor
Moderate
CVE-2026-32629
was published
for
phpmyfaq/phpmyfaq
(Composer)
Mar 31, 2026
A vulnerability exists in the SonicWall Email Security appliance due to improper input...
Low
Unreviewed
CVE-2026-3470
was published
Mar 31, 2026
A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall...
Low
Unreviewed
CVE-2026-3469
was published
Mar 31, 2026
Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows...
High
Unreviewed
CVE-2025-14213
was published
Mar 31, 2026
ProTip!
Advisories are also available from the
GraphQL API