GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
111 advisories
Filter by severity
Incorrect reference resolution in WebView in Google Chrome on on Android prior to 152.0.7977.65...
Moderate
Unreviewed
CVE-2026-79273
was published
Aug 25, 2026
Incorrect reference resolution in CustomTabs in Google Chrome on on Android prior to 152.0.7977...
Moderate
Unreviewed
CVE-2026-79254
was published
Aug 25, 2026
Incorrect reference resolution in Preload in Google Chrome prior to 152.0.7977.65 allowed a...
Moderate
Unreviewed
CVE-2026-79264
was published
Aug 25, 2026
Incorrect reference resolution in Speech in Google Chrome prior to 152.0.7977.65 allowed a remote...
Low
Unreviewed
CVE-2026-79103
was published
Aug 25, 2026
Incorrect reference resolution in Cache in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-79070
was published
Aug 25, 2026
Incorrect reference resolution in Passwords in Google Chrome prior to 152.0.7977.65 allowed a...
Moderate
Unreviewed
CVE-2026-79049
was published
Aug 25, 2026
Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a...
Critical
Unreviewed
CVE-2026-78985
was published
Aug 25, 2026
Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-78942
was published
Aug 25, 2026
phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows...
Critical
Unreviewed
CVE-2026-67602
was published
Aug 24, 2026
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to...
Critical
Unreviewed
CVE-2026-65816
was published
Aug 21, 2026
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos...
Critical
Unreviewed
CVE-2026-13097
was published
Aug 20, 2026
Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169...
Moderate
Unreviewed
CVE-2026-76039
was published
Aug 18, 2026
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference...
High
Unreviewed
CVE-2026-29036
was published
Aug 12, 2026
File Browser: Colliding username normalization gives two users the same home directory
High
CVE-2026-62685
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
A vulnerability was determined in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This impacts the...
Low
Unreviewed
CVE-2026-16120
was published
Jul 18, 2026
OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock...
High
Unreviewed
CVE-2026-62190
was published
Jul 14, 2026
A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of...
Moderate
Unreviewed
CVE-2026-57054
was published
Jul 10, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7,...
Low
Unreviewed
CVE-2025-12506
was published
Jul 8, 2026
cp: -R reads device nodes as streams, destroying device semantics
Moderate
CVE-2026-35358
was published
for
uu_cp
(Rust)
Jul 6, 2026
Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions...
High
Unreviewed
CVE-2026-13372
was published
Jun 26, 2026
Use of an incorrectly resolved name or reference in the pinget backend
in Devolutions UniGetUI...
High
Unreviewed
CVE-2026-10696
was published
Jun 17, 2026
Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
Moderate
CVE-2026-54022
was published
for
open-webui
(pip)
Jun 17, 2026
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
Low
CVE-2026-54282
was published
for
Starlette
(pip)
Jun 15, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7,...
Moderate
Unreviewed
CVE-2026-8716
was published
May 27, 2026
pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad
Moderate
CVE-2026-45306
was published
for
pyload-ng
(pip)
May 14, 2026
ProTip!
Advisories are also available from the
GraphQL API