GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
542 advisories
Filter by severity
An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local...
Moderate
Unreviewed
CVE-2025-66593
was published
May 27, 2026
An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1...
Moderate
Unreviewed
CVE-2025-66592
was published
May 27, 2026
Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows...
Moderate
Unreviewed
CVE-2025-13593
was published
May 27, 2026
Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate...
Critical
Unreviewed
CVE-2026-42901
was published
May 26, 2026
Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
High
CVE-2026-46701
was published
for
network-ai
(npm)
May 21, 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
High
Unreviewed
CVE-2026-34928
was published
May 21, 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
High
Unreviewed
CVE-2026-45207
was published
May 21, 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
High
Unreviewed
CVE-2026-34930
was published
May 21, 2026
An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to...
High
Unreviewed
CVE-2025-71213
was published
May 21, 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
High
Unreviewed
CVE-2026-34929
was published
May 21, 2026
An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service...
High
Unreviewed
CVE-2025-71214
was published
May 21, 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
High
Unreviewed
CVE-2026-45206
was published
May 21, 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
High
Unreviewed
CVE-2026-34927
was published
May 21, 2026
An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection...
High
Unreviewed
CVE-2025-71217
was published
May 21, 2026
NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost...
Moderate
Unreviewed
CVE-2026-40622
was published
May 20, 2026
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path
Critical
GHSA-g53w-w6mj-hrpp
was published
for
github.com/Kuadrant/mcp-gateway
(Go)
May 19, 2026
Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in...
Moderate
Unreviewed
CVE-2026-8971
was published
May 19, 2026
Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in...
Critical
Unreviewed
CVE-2026-8950
was published
May 19, 2026
MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints Enables Browser-Mediated Local Command Execution
Critical
CVE-2026-2611
was published
for
mlflow
(pip)
May 19, 2026
dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transport
High
GHSA-fvh2-gm75-j4j7
was published
for
dynoxide
(npm)
May 18, 2026
Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint
Moderate
CVE-2026-6339
was published
for
github.com/mattermost/mattermost-server
(Go)
May 18, 2026
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because...
High
Unreviewed
CVE-2026-46728
was published
May 17, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
Moderate
CVE-2026-45021
was published
for
github.com/kumahq/kuma
(Go)
May 14, 2026
SillyTavern has Authentication Bypass via SSO Header Injection
Critical
CVE-2026-44649
was published
for
sillytavern
(npm)
May 12, 2026
Unity Catalog has a JWT Issuer Validation Bypass tht Allows Complete User Impersonation
Critical
CVE-2026-27478
was published
for
io.unitycatalog:unitycatalog-server
(Maven)
May 11, 2026
ProTip!
Advisories are also available from the
GraphQL API