GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
2,123 advisories
Filter by severity
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
High
GHSA-94p4-4cq8-9g67
was published
for
GitPython
(pip)
Jul 24, 2026
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
High
GHSA-hr66-5mqr-8mpx
was published
for
@budibase/server
(npm)
Jul 24, 2026
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
High
CVE-2026-59216
was published
for
open-webui
(pip)
Jul 24, 2026
Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802...
High
Unreviewed
CVE-2026-55729
was published
Jul 24, 2026
electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
High
CVE-2026-54673
was published
for
builder-util-runtime
(npm)
Jul 24, 2026
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
High
CVE-2026-45623
was published
for
postcss
(npm)
Jul 23, 2026
The front-end Submissions view did not enforce access control. An unauthenticated visitor could...
High
Unreviewed
CVE-2026-65758
was published
Jul 23, 2026
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware ...
High
Unreviewed
CVE-2026-60371
was published
Jul 23, 2026
n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
High
GHSA-2x35-3fw4-9jr4
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Shared Credential Header Leak via HTTP Request Pagination Expression
High
CVE-2026-59209
was published
for
n8n
(npm)
Jul 22, 2026
Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Internal...
High
Unreviewed
CVE-2026-62560
was published
Jul 22, 2026
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll)....
High
Unreviewed
CVE-2026-62567
was published
Jul 22, 2026
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll...
High
Unreviewed
CVE-2026-62565
was published
Jul 22, 2026
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component:...
High
Unreviewed
CVE-2026-62518
was published
Jul 22, 2026
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create...
High
Unreviewed
CVE-2026-62473
was published
Jul 22, 2026
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite ...
High
Unreviewed
CVE-2026-61267
was published
Jul 22, 2026
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle...
High
Unreviewed
CVE-2026-61240
was published
Jul 22, 2026
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle...
High
Unreviewed
CVE-2026-61185
was published
Jul 22, 2026
Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce ...
High
Unreviewed
CVE-2026-61165
was published
Jul 22, 2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product...
High
Unreviewed
CVE-2026-61159
was published
Jul 22, 2026
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo...
High
Unreviewed
CVE-2026-61133
was published
Jul 22, 2026
Vulnerability in the Oracle Configure to Order product of Oracle E-Business Suite (component:...
High
Unreviewed
CVE-2026-61125
was published
Jul 22, 2026
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite ...
High
Unreviewed
CVE-2026-61116
was published
Jul 22, 2026
Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component:...
High
Unreviewed
CVE-2026-61014
was published
Jul 22, 2026
Vulnerability in the Oracle Capacity product of Oracle E-Business Suite (component: Internal...
High
Unreviewed
CVE-2026-60923
was published
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API