GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,538
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,516
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
166 advisories
Filter by severity
IndexedDB should be cleared when leaving private browsing mode and it is not, the API for...
Moderate
Unreviewed
CVE-2020-12414
was published
May 24, 2022
Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread...
Low
Unreviewed
CVE-2026-9693
was published
Aug 18, 2026
Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may...
Moderate
Unreviewed
CVE-2026-20712
was published
Aug 11, 2026
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose...
Moderate
Unreviewed
CVE-2026-68809
was published
Aug 11, 2026
A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function...
Low
Unreviewed
CVE-2026-19019
was published
Aug 6, 2026
Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and...
Low
Unreviewed
CVE-2026-63545
was published
Aug 3, 2026
better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin,...
Moderate
Unreviewed
CVE-2026-67334
was published
Aug 1, 2026
Xenstore, to have an up-to-date picture of the entire system, wants to
know of domains appearing...
High
Unreviewed
CVE-2026-42492
was published
Jul 28, 2026
Software installed and run as a non-privileged user may conduct a sequence of improper GPU system...
High
Unreviewed
CVE-2026-7639
was published
Jul 10, 2026
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
Low
GHSA-2vg6-77g8-24mp
was published
for
@better-auth/scim
(npm)
Jul 7, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
Low
CVE-2026-35361
was published
for
uu_mknod
(Rust)
Jul 6, 2026
zebrad has persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tip
Moderate
CVE-2026-52733
was published
for
zebra-state
(Rust)
Jul 2, 2026
Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache
High
CVE-2026-52736
was published
for
zebra-state
(Rust)
Jul 2, 2026
Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads
Moderate
CVE-2026-5038
was published
for
multer
(npm)
Jun 17, 2026
Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage...
Moderate
Unreviewed
CVE-2026-53867
was published
Jun 13, 2026
Apache Tomcat Incomplete Cleanup vulnerability
Moderate
CVE-2023-42795
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 10, 2023
In the Linux kernel, the following vulnerability has been resolved:
drm/xe/sync: Cleanup...
Moderate
Unreviewed
CVE-2026-43395
was published
May 8, 2026
Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged...
Moderate
Unreviewed
CVE-2026-0427
was published
May 15, 2026
In the Linux kernel, the following vulnerability has been resolved:
tpm: Clean up TPM space...
Moderate
Unreviewed
CVE-2024-49851
was published
Oct 21, 2024
Due to improper Spring Security configuration, SAP Commerce cloud allows an unauthenticated user...
Critical
Unreviewed
CVE-2026-34263
was published
May 12, 2026
Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain...
High
Unreviewed
CVE-2025-66467
was published
May 8, 2026
nesquena hermes-webui contains an environment variable leakage vulnerability where profile...
Moderate
Unreviewed
CVE-2026-6830
was published
Apr 22, 2026
Oracle Formsbuilder 9.0.4 stores database usernames and passwords in a temporary file, which is...
Low
Unreviewed
CVE-2005-2293
was published
May 1, 2022
BestCrypt BCWipe 1.0.7 and 2.0 through 2.35.1 does not clear Windows alternate data streams that...
Moderate
Unreviewed
CVE-2002-2066
was published
Apr 30, 2022
ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not...
Low
Unreviewed
CVE-2000-0552
was published
Apr 30, 2022
ProTip!
Advisories are also available from the
GraphQL API