GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
1,188 advisories
Filter by severity
HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to...
Low
Unreviewed
CVE-2026-56584
was published
Jul 21, 2026
File Browser: Share API exposes the password hash and bypass token
Low
CVE-2026-62684
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability....
Low
Unreviewed
CVE-2026-35145
was published
Jul 16, 2026
HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails...
Low
Unreviewed
CVE-2026-35143
was published
Jul 16, 2026
HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie...
Low
Unreviewed
CVE-2026-35140
was published
Jul 16, 2026
HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application...
Low
Unreviewed
CVE-2026-35142
was published
Jul 16, 2026
CVE-2026-40956
is a memory disclosure vulnerability in Secure Access client versions prior to 14...
Low
Unreviewed
CVE-2026-40956
was published
Jul 15, 2026
Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited...
Low
Unreviewed
CVE-2026-48001
was published
Jul 14, 2026
Insertion of sensitive information into a file in the Recovery Kit response file generation...
Low
Unreviewed
CVE-2026-15642
was published
Jul 14, 2026
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized...
Low
Unreviewed
CVE-2026-50419
was published
Jul 14, 2026
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized...
Low
Unreviewed
CVE-2026-50416
was published
Jul 14, 2026
A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This vulnerability...
Low
Unreviewed
CVE-2026-15627
was published
Jul 14, 2026
A vulnerability was found in zhayujie CowAgent up to 2.1.0. This issue affects the function...
Low
Unreviewed
CVE-2026-15329
was published
Jul 10, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth
Low
CVE-2026-49254
was published
for
d7y.io/dragonfly/v2
(Go)
Jul 2, 2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation...
Low
Unreviewed
CVE-2026-58036
was published
Jul 1, 2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation...
Low
Unreviewed
CVE-2026-58026
was published
Jul 1, 2026
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information...
Low
Unreviewed
CVE-2026-9836
was published
Jun 30, 2026
parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change
Low
GHSA-97pr-9hgg-3p8r
was published
for
parse-server
(npm)
Jun 19, 2026
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA...
Low
Unreviewed
CVE-2026-46977
was published
Jun 17, 2026
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). ...
Low
Unreviewed
CVE-2026-46874
was published
Jun 17, 2026
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA...
Low
Unreviewed
CVE-2026-46815
was published
Jun 17, 2026
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA...
Low
Unreviewed
CVE-2026-46816
was published
Jun 17, 2026
Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`
Low
GHSA-rq7w-g337-39qq
was published
for
nuxt
(npm)
Jun 15, 2026
@babel/core: Arbitrary File Read via sourceMappingURL Comment
Low
CVE-2026-49356
was published
for
@babel/core
(npm)
Jun 15, 2026
A vulnerability was identified in JeecgBoot up to 3.9.2. Affected by this vulnerability is the...
Low
Unreviewed
CVE-2026-11464
was published
Jun 8, 2026
ProTip!
Advisories are also available from the
GraphQL API