GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
298 advisories
Filter by severity
Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container
Moderate
CVE-2026-50565
was published
for
github.com/fission/fission
(Go)
Jun 30, 2026
Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate...
Critical
Unreviewed
CVE-2026-48584
was published
Jun 19, 2026
Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
Moderate
CVE-2026-54319
was published
for
github.com/daytonaio/daytona
(Go)
Jun 18, 2026
A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop...
High
Unreviewed
CVE-2026-12505
was published
Jun 18, 2026
Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a...
Critical
Unreviewed
CVE-2026-12027
was published
Jun 12, 2026
CleanWipe Removal Tool (macOS), prior to 16.0.0.65, may be susceptible to an Local Privilege...
Moderate
Unreviewed
CVE-2026-11626
was published
Jun 10, 2026
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected...
High
Unreviewed
CVE-2026-46748
was published
Jun 9, 2026
actual Allows Electron to Run As Node
Moderate
CVE-2026-42890
was published
for
actual
(npm)
Jun 8, 2026
Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53...
Critical
Unreviewed
CVE-2026-11167
was published
Jun 5, 2026
A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS....
High
Unreviewed
CVE-2026-10843
was published
Jun 4, 2026
A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local...
High
Unreviewed
CVE-2025-12694
was published
Jun 4, 2026
Local privilege escalation due to excessive permissions assigned to child processes. The...
High
Unreviewed
CVE-2026-42061
was published
Jun 3, 2026
IPAM controller service account granted unnecessary full access to Secrets
Moderate
CVE-2026-47190
was published
for
github.com/metal3-io/ip-address-manager
(Go)
May 29, 2026
IBM Netezza Performance Server Replication Services 3.0.2.0 through 3.0.5.0 allows an attacker...
High
Unreviewed
CVE-2026-3623
was published
May 27, 2026
Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables
Moderate
CVE-2026-46618
was published
for
github.com/fission/fission
(Go)
May 21, 2026
Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read
High
CVE-2026-46617
was published
for
github.com/fission/fission
(Go)
May 21, 2026
Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on...
High
Unreviewed
CVE-2026-8370
was published
May 19, 2026
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on...
High
Unreviewed
CVE-2026-29205
was published
May 14, 2026
A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with...
High
Unreviewed
CVE-2026-32673
was published
May 13, 2026
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated...
High
Unreviewed
CVE-2026-32643
was published
May 13, 2026
The new upstream added a privileged D-Bus
helper called plasmaloginauthhelper, which suffers from...
High
Unreviewed
CVE-2026-25710
was published
May 13, 2026
Execution with unnecessary privileges in Microsoft Dynamics 365 (on-premises) allows an...
Critical
Unreviewed
CVE-2026-42833
was published
May 12, 2026
Dell PowerScale InsightIQ, versions 5.0.0 through 6.2.0, contains an execution with unnecessary...
Moderate
Unreviewed
CVE-2026-40638
was published
May 12, 2026
CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE
Critical
CVE-2026-44477
was published
for
github.com/cloudnative-pg/cloudnative-pg
(Go)
May 11, 2026
mpGabinet is vulnerable to Privilege Escalation due to excessive database privileges assigned to...
Moderate
Unreviewed
CVE-2026-40550
was published
Apr 28, 2026
ProTip!
Advisories are also available from the
GraphQL API