GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
76 advisories
Filter by severity
A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole...
Moderate
Unreviewed
CVE-2026-71846
was published
Aug 13, 2026
Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container
Moderate
CVE-2026-50565
was published
for
github.com/fission/fission
(Go)
Jun 30, 2026
Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
Moderate
CVE-2026-54319
was published
for
github.com/daytonaio/daytona
(Go)
Jun 18, 2026
CleanWipe Removal Tool (macOS), prior to 16.0.0.65, may be susceptible to an Local Privilege...
Moderate
Unreviewed
CVE-2026-11626
was published
Jun 10, 2026
actual Allows Electron to Run As Node
Moderate
CVE-2026-42890
was published
for
actual
(npm)
Jun 8, 2026
IPAM controller service account granted unnecessary full access to Secrets
Moderate
CVE-2026-47190
was published
for
github.com/metal3-io/ip-address-manager
(Go)
May 29, 2026
Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables
Moderate
CVE-2026-46618
was published
for
github.com/fission/fission
(Go)
May 21, 2026
Dell PowerScale InsightIQ, versions 5.0.0 through 6.2.0, contains an execution with unnecessary...
Moderate
Unreviewed
CVE-2026-40638
was published
May 12, 2026
mpGabinet is vulnerable to Privilege Escalation due to excessive database privileges assigned to...
Moderate
Unreviewed
CVE-2026-40550
was published
Apr 28, 2026
Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain an Execution with...
Moderate
Unreviewed
CVE-2026-25908
was published
Apr 27, 2026
Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission...
Moderate
Unreviewed
CVE-2026-3315
was published
Mar 10, 2026
OliveTin's RestartAction always runs actions as guest
Moderate
CVE-2026-30225
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
A vulnerability in the CLI of Cisco Secure FTD Software could allow an authenticated, local...
Moderate
Unreviewed
CVE-2026-20017
was published
Mar 4, 2026
Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1,...
Moderate
Unreviewed
CVE-2026-21426
was published
Mar 4, 2026
Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1,...
Moderate
Unreviewed
CVE-2026-21424
was published
Mar 4, 2026
Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1,...
Moderate
Unreviewed
CVE-2026-21421
was published
Mar 4, 2026
A vulnerability in the NX-OS CLI privilege levels of Cisco UCS Manager Software could allow an...
Moderate
Unreviewed
CVE-2026-20037
was published
Feb 25, 2026
Local privilege escalation in Genetec Sipelia Plugin. An authenticated low-privileged Windows...
Moderate
Unreviewed
CVE-2025-1790
was published
Feb 13, 2026
A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive...
Moderate
Unreviewed
CVE-2026-22549
was published
Feb 4, 2026
Brocade Fabric OS before 9.2.1 has a vulnerability that could allow a local authenticated...
Moderate
Unreviewed
CVE-2025-58379
was published
Feb 3, 2026
IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through...
Moderate
Unreviewed
CVE-2025-36059
was published
Jan 20, 2026
Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard
Moderate
CVE-2026-23528
was published
for
distributed
(pip)
Jan 16, 2026
Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application, version(s) versions 5.26 to 5.30...
Moderate
Unreviewed
CVE-2025-46696
was published
Jan 6, 2026
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall...
Moderate
Unreviewed
CVE-2025-40602
was published
Dec 18, 2025
A Execution with Unnecessary Privileges vulnerability in lightdm-kde-greeter allows escalation...
Moderate
Unreviewed
CVE-2025-62876
was published
Nov 12, 2025
ProTip!
Advisories are also available from the
GraphQL API