GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,535
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,515
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
106 advisories
Filter by severity
MagicMirror: ssrf calendar .js
Moderate
CVE-2026-63643
was published
for
magicmirror
(npm)
Aug 18, 2026
Astro: Unauthenticated path override in the @astrojs/vercel ISR function
Moderate
CVE-2026-73424
was published
for
@astrojs/vercel
(npm)
Jul 20, 2026
The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an...
Moderate
Unreviewed
CVE-2026-72640
was published
Aug 13, 2026
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An...
High
Unreviewed
CVE-2026-73266
was published
Aug 13, 2026
A flaw was found in the multicloud-integrations component. The Application propagation controller...
Critical
Unreviewed
CVE-2026-72526
was published
Aug 12, 2026
A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management ...
Critical
Unreviewed
CVE-2026-70398
was published
Aug 12, 2026
A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create...
Moderate
Unreviewed
CVE-2026-16456
was published
Aug 10, 2026
The OnCallNotificationActivity in the Datadog Android application is declared android:exported=...
Moderate
Unreviewed
CVE-2026-44964
was published
Aug 7, 2026
PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
Moderate
CVE-2026-48522
was published
for
PyJWT
(pip)
Jun 15, 2026
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster...
High
Unreviewed
CVE-2026-17107
was published
Jul 24, 2026
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
Moderate
CVE-2026-54663
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor
High
CVE-2026-43910
was published
for
io.appium:java-client
(Maven)
Jul 28, 2026
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary...
Critical
Unreviewed
CVE-2026-42933
was published
Jul 24, 2026
An authenticated user with write privileges on a Queryable Encryption-enabled collection may be...
High
Unreviewed
CVE-2026-13062
was published
Jul 22, 2026
NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint
Moderate
CVE-2026-53931
was published
for
nocodb
(npm)
Jun 17, 2026
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
High
CVE-2026-53514
was published
for
better-auth
(npm)
Jul 7, 2026
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
Critical
CVE-2026-53513
was published
for
@better-auth/sso
(npm)
Jul 7, 2026
Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities
Moderate
CVE-2026-50169
was published
for
@angular/service-worker
(npm)
Jun 15, 2026
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode
High
CVE-2026-54628
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior...
Moderate
Unreviewed
CVE-2026-12879
was published
Jul 9, 2026
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
Moderate
CVE-2026-55430
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration
High
CVE-2026-49821
was published
for
github.com/fission/fission
(Go)
Jun 30, 2026
Strimzi: Cross-namespace privilege escalation via `Kafka.spec.entityOperator`
High
CVE-2026-55225
was published
for
io.strimzi:strimzi
(Maven)
Jun 18, 2026
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
Moderate
CVE-2026-9595
was published
for
webpack-dev-server
(npm)
Jun 17, 2026
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
High
CVE-2026-53999
was published
for
github.com/radius-project/radius
(Go)
Jun 12, 2026
ProTip!
Advisories are also available from the
GraphQL API