GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,535
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,515
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
296 advisories
Filter by severity
NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an...
High
Unreviewed
CVE-2026-24183
was published
Aug 18, 2026
A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole...
Moderate
Unreviewed
CVE-2026-71846
was published
Aug 13, 2026
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster...
Critical
Unreviewed
CVE-2026-72508
was published
Aug 12, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security...
High
Unreviewed
CVE-2026-17445
was published
Aug 12, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote...
High
Unreviewed
CVE-2026-18669
was published
Aug 12, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
High
Unreviewed
CVE-2026-17110
was published
Aug 12, 2026
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows...
High
Unreviewed
CVE-2026-59133
was published
Aug 11, 2026
A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard...
High
Unreviewed
CVE-2026-18982
was published
Aug 10, 2026
A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the...
High
Unreviewed
CVE-2026-18949
was published
Aug 10, 2026
A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which...
High
Unreviewed
CVE-2026-18608
was published
Aug 10, 2026
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions,...
High
Unreviewed
CVE-2026-67609
was published
Aug 3, 2026
When applying replicated changes for a row that is missing one or more columns, pglogical...
Critical
Unreviewed
CVE-2026-50737
was published
Jul 28, 2026
Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during...
High
Unreviewed
CVE-2026-14172
was published
Jul 24, 2026
A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core...
High
Unreviewed
CVE-2026-8933
was published
Jul 21, 2026
A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal...
High
Unreviewed
CVE-2026-15226
was published
Jul 21, 2026
A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the...
High
Unreviewed
CVE-2026-13104
was published
Jul 16, 2026
A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. The...
High
Unreviewed
CVE-2026-15584
was published
Jul 13, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects...
Critical
Unreviewed
CVE-2026-42486
was published
Jul 9, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects...
Critical
Unreviewed
CVE-2026-23562
was published
Jul 9, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects...
Critical
Unreviewed
CVE-2026-23560
was published
Jul 9, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects...
Critical
Unreviewed
CVE-2026-23561
was published
Jul 9, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects...
Critical
Unreviewed
CVE-2026-23559
was published
Jul 9, 2026
Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation
Critical
CVE-2026-50566
was published
for
github.com/fission/fission
(Go)
Jun 30, 2026
Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container
Moderate
CVE-2026-50565
was published
for
github.com/fission/fission
(Go)
Jun 30, 2026
Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate...
Critical
Unreviewed
CVE-2026-48584
was published
Jun 19, 2026
ProTip!
Advisories are also available from the
GraphQL API