GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
10,964 advisories
Filter by severity
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive...
Moderate
Unreviewed
CVE-2026-44276
was published
Jul 22, 2026
There is a information disclosure vulnerability in some Hikvision cameras, allowing...
Moderate
Unreviewed
CVE-2026-61392
was published
Jul 22, 2026
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll...
High
Unreviewed
CVE-2026-62565
was published
Jul 22, 2026
Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Internal...
High
Unreviewed
CVE-2026-62560
was published
Jul 22, 2026
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll)....
High
Unreviewed
CVE-2026-62567
was published
Jul 22, 2026
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal...
Moderate
Unreviewed
CVE-2026-62559
was published
Jul 22, 2026
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal...
Moderate
Unreviewed
CVE-2026-62556
was published
Jul 22, 2026
Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality...
Moderate
Unreviewed
CVE-2026-62525
was published
Jul 22, 2026
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll -...
Moderate
Unreviewed
CVE-2026-62524
was published
Jul 22, 2026
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component:...
High
Unreviewed
CVE-2026-62518
was published
Jul 22, 2026
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component:...
Moderate
Unreviewed
CVE-2026-62490
was published
Jul 22, 2026
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create...
High
Unreviewed
CVE-2026-62473
was published
Jul 22, 2026
Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite ...
Moderate
Unreviewed
CVE-2026-62470
was published
Jul 22, 2026
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal...
Moderate
Unreviewed
CVE-2026-62453
was published
Jul 22, 2026
Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI). ...
Moderate
Unreviewed
CVE-2026-61316
was published
Jul 22, 2026
Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Proposals). ...
Moderate
Unreviewed
CVE-2026-61279
was published
Jul 22, 2026
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
High
GHSA-rwj8-pgh3-r573
was published
for
gitpython
(pip)
Jul 21, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API
Low
CVE-2026-58511
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
Moderate
CVE-2026-57897
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
Moderate
CVE-2026-58510
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
Moderate
CVE-2026-58427
was published
for
gitea.dev
(Go)
Jul 21, 2026
Gitea: Notification API leaks private issue metadata after access revocation
High
CVE-2026-58419
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Unauthorized Access to Labels of Private Organizations
High
CVE-2026-25038
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private
High
CVE-2026-24451
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the...
High
Unreviewed
CVE-2026-52474
was published
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API