GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
95 advisories
Filter by severity
docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace...
High
Unreviewed
CVE-2026-78122
was published
Aug 23, 2026
A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows...
High
Unreviewed
CVE-2026-40145
was published
Aug 17, 2026
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied...
Moderate
Unreviewed
CVE-2026-68868
was published
Aug 12, 2026
Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized...
High
Unreviewed
CVE-2026-62721
was published
Aug 11, 2026
Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable...
Moderate
Unreviewed
CVE-2025-31938
was published
Aug 11, 2026
A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a...
Moderate
Unreviewed
CVE-2026-16560
was published
Jul 22, 2026
Insufficient granularity of access control in Windows Event Logging Service allows an authorized...
High
Unreviewed
CVE-2026-50502
was published
Jul 14, 2026
Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an...
High
Unreviewed
CVE-2026-50405
was published
Jul 14, 2026
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows...
High
Unreviewed
CVE-2026-56155
was published
Jul 14, 2026
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized...
High
Unreviewed
CVE-2026-55006
was published
Jul 14, 2026
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to...
High
Unreviewed
CVE-2026-48581
was published
Jul 14, 2026
A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's...
Moderate
Unreviewed
CVE-2026-14615
was published
Jul 3, 2026
Keycloak: Information disclosure due to user profile permission bypass
Low
CVE-2026-9088
was published
for
org.keycloak:keycloak-services
(Maven)
Jun 5, 2026
Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker...
High
Unreviewed
CVE-2021-46747
was published
Jun 1, 2026
MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
Critical
CVE-2026-2651
was published
for
mlflow
(pip)
May 26, 2026
Keycloak Account Resources user lookup contains broken access control
Moderate
CVE-2026-37981
was published
for
org.keycloak:keycloak-services
(Maven)
May 19, 2026
Improper isolation of shared resources within the CPU operation cache on Zen 2-based products...
High
Unreviewed
CVE-2025-54518
was published
May 15, 2026
Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary...
High
Unreviewed
CVE-2024-21962
was published
May 15, 2026
Insufficient granularity of access control in Microsoft Office SharePoint allows an authorized...
High
Unreviewed
CVE-2026-40365
was published
May 12, 2026
Insufficient granularity of access control in Microsoft Office Click-To-Run allows an authorized...
High
Unreviewed
CVE-2026-35436
was published
May 12, 2026
OpenClaw: Agent gateway config mutations could change protected operator settings
Moderate
GHSA-7jm2-g593-4qrc
was published
for
openclaw
(npm)
Apr 25, 2026
Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record
Moderate
CVE-2026-38743
was published
for
apache-airflow
(pip)
Apr 24, 2026
Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions
Moderate
CVE-2026-40690
was published
for
apache-airflow
(pip)
Apr 24, 2026
A vulnerability in the web application allows standard users to escalate their privileges to...
Critical
Unreviewed
CVE-2026-6356
was published
Apr 22, 2026
Paperclip: Cross-tenant agent API token minting via missing assertCompanyAccess on /api/agents/:id/keys
Critical
GHSA-47wq-cj9q-wpmp
was published
for
@paperclipai/server
(npm)
Apr 16, 2026
ProTip!
Advisories are also available from the
GraphQL API