GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,630
Maven
5,000+
npm
5,000+
NuGet
928
pip
4,850
Pub
13
RubyGems
1,045
Rust
1,301
Swift
53
Unreviewed advisories
All unreviewed
5,000+
329,564 advisories
Filter by severity
A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an...
Moderate
Unreviewed
CVE-2026-7505
was published
May 1, 2026
A vulnerability was determined in OWAP DefectDojo up to 2.55.4. Affected by this vulnerability is...
Low
Unreviewed
CVE-2026-7510
was published
May 1, 2026
Route Services can be leveraged to send app traffic to network destinations outside of an app's...
Moderate
Unreviewed
CVE-2026-22726
was published
May 1, 2026
RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of...
High
Unreviewed
CVE-2026-5405
was published
May 1, 2026
A flaw has been found in UTT HiPER 1200GW up to 2.5.3-1703. The affected element is the function...
High
Unreviewed
CVE-2026-7512
was published
May 1, 2026
K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Moderate
Unreviewed
CVE-2026-5404
was published
May 1, 2026
Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of...
High
Unreviewed
CVE-2026-5656
was published
May 1, 2026
A vulnerability has been found in UTT HiPER 1200GW up to 2.5.3-170306. The impacted element is...
High
Unreviewed
CVE-2026-7513
was published
May 1, 2026
SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and...
High
Unreviewed
CVE-2026-5403
was published
May 1, 2026
A vulnerability was found in Bootstrap CMS 0.9.0-alpha. Affected is an unknown function of the...
Low
Unreviewed
CVE-2026-7508
was published
May 1, 2026
A vulnerability has been found in SourceCodester Hotel Management System 1.0. This impacts an...
Moderate
Unreviewed
CVE-2026-7506
was published
May 1, 2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Unknown
Unreviewed
CVE-2026-4178
was published
May 1, 2026
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes...
Moderate
Unreviewed
CVE-2025-36122
was published
May 1, 2026
IBM Langflow Desktop <=1.8.4 Langflow could allow a remote attacker to traverse directories on...
Moderate
Unreviewed
CVE-2026-3345
was published
May 1, 2026
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes...
Moderate
Unreviewed
CVE-2025-14688
was published
May 1, 2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text...
Moderate
Unreviewed
CVE-2025-36335
was published
May 1, 2026
IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction...
Moderate
Unreviewed
CVE-2026-6542
was published
May 1, 2026
IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary...
High
Unreviewed
CVE-2026-6543
was published
May 1, 2026
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a...
Moderate
Unreviewed
CVE-2026-40685
was published
May 1, 2026
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes...
Moderate
Unreviewed
CVE-2026-1577
was published
May 1, 2026
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the...
Moderate
Unreviewed
CVE-2026-40684
was published
May 1, 2026
A vulnerability was detected in code-projects for Plugin 4.1.2cu.5137. The impacted element is...
High
Unreviewed
CVE-2026-7503
was published
May 1, 2026
HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command...
High
Unreviewed
CVE-2026-7551
was published
May 1, 2026
IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between...
Moderate
Unreviewed
CVE-2025-36180
was published
May 1, 2026
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA...
Moderate
Unreviewed
CVE-2026-40687
was published
May 1, 2026
ProTip!
Advisories are also available from the
GraphQL API