GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
314 advisories
Filter by severity
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)...
Critical
Unreviewed
CVE-2026-60294
was published
Jul 22, 2026
Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
Critical
GHSA-mqhr-6j6h-74p5
was published
for
@budibase/server
(npm)
Jul 24, 2026
Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in...
Critical
Unreviewed
CVE-2026-65760
was published
Jul 23, 2026
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component...
Critical
Unreviewed
CVE-2026-61175
was published
Jul 22, 2026
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). ...
Critical
Unreviewed
CVE-2026-60264
was published
Jul 22, 2026
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft...
Critical
Unreviewed
CVE-2026-61233
was published
Jul 22, 2026
Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153 and...
Critical
Unreviewed
CVE-2026-16387
was published
Jul 21, 2026
An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the...
Critical
Unreviewed
CVE-2026-51027
was published
Jul 20, 2026
PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
Critical
CVE-2026-57116
was published
for
praisonai
(pip)
Jun 18, 2026
An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain...
Critical
Unreviewed
CVE-2026-52101
was published
Jul 14, 2026
TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation
Critical
GHSA-g936-7jqj-mwv8
was published
for
github.com/almeidapaulopt/tsdproxy
(Go)
Jul 10, 2026
9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
Critical
CVE-2026-55500
was published
for
9router
(npm)
Jul 6, 2026
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
Critical
GHSA-vjc7-jrh9-9j86
was published
for
9router
(npm)
Jul 6, 2026
LaunchServer FileServerHandler has an unauthenticated path traversal issue
Critical
CVE-2026-54617
was published
for
pro.gravit.launcher:launchserver-api
(Maven)
Jul 2, 2026
Vulnerability involving the exposure of sensitive data provided without adequate protection. The...
Critical
Unreviewed
CVE-2026-7166
was published
Jun 22, 2026
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
Critical
CVE-2026-55447
was published
for
langflow
(pip)
Jun 19, 2026
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
Critical
CVE-2026-55450
was published
for
langflow
(pip)
Jun 17, 2026
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web...
Critical
Unreviewed
CVE-2026-46912
was published
Jun 17, 2026
HAXcms: Private Key Disclosure via Broken HMAC Implementation
Critical
CVE-2026-46395
was published
for
@haxtheweb/haxcms-nodejs
(npm)
May 19, 2026
http4k has a potential XXE (XML External Entity Injection) vulnerability
Critical
CVE-2024-55875
was published
for
org.http4k:http4k-format-xml
(Maven)
Dec 12, 2024
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ariva Computer Accord...
Critical
Unreviewed
CVE-2024-1744
was published
Sep 6, 2024
Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure....
Critical
Unreviewed
CVE-2026-40965
was published
Jun 2, 2026
Strapi may leak sensitive data via relational filtering due to lack of query sanitization
Critical
CVE-2026-27886
was published
for
@strapi/strapi
(npm)
May 14, 2026
Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an...
Critical
Unreviewed
CVE-2026-41615
was published
May 14, 2026
sealed-env: TOTP secret embedded in unseal token payload (enterprise mode)
Critical
CVE-2026-45091
was published
for
io.github.davidalmeidac:sealed-env-core
(Maven)
May 12, 2026
ProTip!
Advisories are also available from the
GraphQL API