GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
52 advisories
Filter by severity
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to...
Critical
Unreviewed
CVE-2026-70496
was published
Aug 19, 2026
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster...
Critical
Unreviewed
CVE-2026-72508
was published
Aug 12, 2026
When applying replicated changes for a row that is missing one or more columns, pglogical...
Critical
Unreviewed
CVE-2026-50737
was published
Jul 28, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects...
Critical
Unreviewed
CVE-2026-23562
was published
Jul 9, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects...
Critical
Unreviewed
CVE-2026-42486
was published
Jul 9, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects...
Critical
Unreviewed
CVE-2026-23559
was published
Jul 9, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects...
Critical
Unreviewed
CVE-2026-23560
was published
Jul 9, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects...
Critical
Unreviewed
CVE-2026-23561
was published
Jul 9, 2026
Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation
Critical
CVE-2026-50566
was published
for
github.com/fission/fission
(Go)
Jun 30, 2026
Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate...
Critical
Unreviewed
CVE-2026-48584
was published
Jun 19, 2026
Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a...
Critical
Unreviewed
CVE-2026-12027
was published
Jun 12, 2026
Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53...
Critical
Unreviewed
CVE-2026-11167
was published
Jun 5, 2026
Execution with unnecessary privileges in Microsoft Dynamics 365 (on-premises) allows an...
Critical
Unreviewed
CVE-2026-42833
was published
May 12, 2026
CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE
Critical
CVE-2026-44477
was published
for
github.com/cloudnative-pg/cloudnative-pg
(Go)
May 11, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
Critical
GHSA-2wvh-87g2-89hr
was published
for
openc3
(RubyGems)
Apr 23, 2026
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container...
Critical
Unreviewed
CVE-2026-1346
was published
Apr 8, 2026
An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0....
Critical
Unreviewed
CVE-2026-34877
was published
Apr 2, 2026
An issue was discovered in Percona PMM before 3.7. Because an internal database user retains...
Critical
Unreviewed
CVE-2026-25212
was published
Apr 2, 2026
GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level...
Critical
Unreviewed
CVE-2026-4606
was published
Mar 23, 2026
IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user...
Critical
Unreviewed
CVE-2025-13375
was published
Feb 4, 2026
A vulnerability has been identified in the ServiceNow AI Platform that could enable an...
Critical
Unreviewed
CVE-2025-12420
was published
Jan 13, 2026
NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with...
Critical
Unreviewed
CVE-2025-33224
was published
Dec 23, 2025
NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with...
Critical
Unreviewed
CVE-2025-33223
was published
Dec 23, 2025
Neuron MySQLWriteTool allows arbitrary/destructive SQL when exposed to untrusted prompts (agent “footgun”)
Critical
CVE-2025-67510
was published
for
neuron-core/neuron-ai
(Composer)
Dec 9, 2025
Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges...
Critical
Unreviewed
CVE-2025-34274
was published
Oct 31, 2025
ProTip!
Advisories are also available from the
GraphQL API