GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,521
Maven
5,000+
npm
5,000+
NuGet
911
pip
4,760
Pub
13
RubyGems
1,036
Rust
1,229
Swift
53
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
4,892 advisories
Filter by severity
Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input Validation...
Moderate
Unreviewed
CVE-2026-27299
was published
Apr 15, 2026
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2026-32201
was published
Apr 14, 2026
Improper input validation in Windows Hello allows an authorized attacker to bypass a security...
Moderate
Unreviewed
CVE-2026-27906
was published
Apr 14, 2026
The bson_validate function may return early on specific inputs and incorrectly report success....
Moderate
Unreviewed
CVE-2026-6231
was published
Apr 13, 2026
Out-of-bounds write vulnerability in the kernel module.
Impact: Successful exploitation of this...
Moderate
Unreviewed
CVE-2026-34855
was published
Apr 13, 2026
Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 147...
Moderate
Unreviewed
CVE-2026-5887
was published
Apr 9, 2026
Insufficient validation of untrusted input in WebML in Google Chrome on Windows prior to 147.0...
Moderate
Unreviewed
CVE-2026-5885
was published
Apr 9, 2026
Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 147.0.7727.55...
Moderate
Unreviewed
CVE-2026-5919
was published
Apr 9, 2026
A vulnerability was found in pytries datrie up to 0.8.3. The affected element is the function...
Moderate
Unreviewed
CVE-2026-5659
was published
Apr 6, 2026
A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function...
Moderate
Unreviewed
CVE-2026-5536
was published
Apr 5, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from...
Moderate
Unreviewed
CVE-2026-29137
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag...
Moderate
Unreviewed
CVE-2026-29135
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with...
Moderate
Unreviewed
CVE-2026-29133
was published
Apr 2, 2026
A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the...
Moderate
Unreviewed
CVE-2026-30523
was published
Apr 1, 2026
MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file...
Moderate
Unreviewed
CVE-2026-29909
was published
Mar 30, 2026
When sending invalid base64 SASL data, login process is disconnected from the auth server,...
Moderate
Unreviewed
CVE-2025-59028
was published
Mar 27, 2026
A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the...
Moderate
Unreviewed
CVE-2026-4860
was published
Mar 26, 2026
A stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7...
Moderate
Unreviewed
CVE-2026-28852
was published
Mar 25, 2026
A validation issue existed in the entitlement verification. This issue was addressed with...
Moderate
Unreviewed
CVE-2026-28821
was published
Mar 25, 2026
This issue was addressed with improved input validation. This issue is fixed in iOS 26.3 and...
Moderate
Unreviewed
CVE-2026-20686
was published
Mar 25, 2026
A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of...
Moderate
Unreviewed
CVE-2026-4538
was published
Mar 22, 2026
The Appmax plugin for WordPress is vulnerable to Improper Input Validation in all versions up to,...
Moderate
Unreviewed
CVE-2026-3641
was published
Mar 21, 2026
The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object...
Moderate
Unreviewed
CVE-2026-3460
was published
Mar 21, 2026
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the...
Moderate
Unreviewed
CVE-2026-4438
was published
Mar 20, 2026
Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox...
Moderate
Unreviewed
CVE-2026-33369
was published
Mar 20, 2026
ProTip!
Advisories are also available from the
GraphQL API