GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
280 advisories
Filter by severity
This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint...
Moderate
Unreviewed
CVE-2026-11970
was published
Aug 13, 2026
Improper conditions check for the Intel(R) NPU Driver for all versions within Ring 3: User...
Moderate
Unreviewed
CVE-2026-20769
was published
Aug 11, 2026
Improper conditions check in the firmware for the Intel(R) NPU Driver for all versions within...
Moderate
Unreviewed
CVE-2026-20783
was published
Aug 11, 2026
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo...
Moderate
Unreviewed
CVE-2026-59693
was published
Aug 11, 2026
Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers...
Moderate
Unreviewed
CVE-2025-71413
was published
Aug 7, 2026
In imgsensor, there is a possible application crash due to incorrect error handling. This could...
Moderate
Unreviewed
CVE-2026-20486
was published
Aug 3, 2026
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
Moderate
CVE-2026-73429
was published
for
russh
(Rust)
Jul 24, 2026
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
Moderate
CVE-2026-73430
was published
for
russh
(Rust)
Jul 24, 2026
With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and...
Moderate
Unreviewed
CVE-2026-44621
was published
Jul 22, 2026
Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking...
Moderate
Unreviewed
CVE-2026-8075
was published
Jul 17, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding...
Moderate
Unreviewed
CVE-2026-57031
was published
Jul 10, 2026
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an...
Moderate
Unreviewed
CVE-2026-0287
was published
Jul 9, 2026
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)
Moderate
CVE-2026-35366
was published
for
uu_printenv
(Rust)
Jul 6, 2026
kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)
Moderate
CVE-2026-35369
was published
for
uu_kill
(Rust)
Jul 6, 2026
zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers
Moderate
GHSA-c8w6-x74f-vmg3
was published
for
zebra-rpc
(Rust)
Jul 2, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
Moderate
GHSA-4v76-cw68-4vc9
was published
for
surrealdb
(Rust)
Jul 1, 2026
CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
Moderate
CVE-2026-54775
was published
for
CoreWCF.Kafka
(NuGet)
Jun 19, 2026
protobufjs : Schema-derived names can shadow runtime-significant properties
Moderate
CVE-2026-54269
was published
for
protobufjs
(npm)
Jun 15, 2026
A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN...
Moderate
Unreviewed
CVE-2026-0269
was published
Jun 11, 2026
Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing
Moderate
CVE-2026-4915
was published
for
github.com/mattermost/mattermost-server
(Go)
May 26, 2026
Improper Check for Unusual or Exceptional Conditions vulnerability in Samsung Open Source...
Moderate
Unreviewed
CVE-2026-47315
was published
May 19, 2026
Mattermost doesn't validate the response body of proxied images
Moderate
CVE-2026-4054
was published
for
github.com/mattermost/mattermost-server
(Go)
May 15, 2026
Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass...
Moderate
Unreviewed
CVE-2026-0241
was published
May 13, 2026
A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally...
Moderate
Unreviewed
CVE-2026-0235
was published
May 13, 2026
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an...
Moderate
Unreviewed
CVE-2026-0262
was published
May 13, 2026
ProTip!
Advisories are also available from the
GraphQL API