GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
172,613 advisories
Filter by severity
The application protects access through its calculator-style vault passcode, but the stored data...
Moderate
Unreviewed
CVE-2026-77875
was published
Sep 19, 2026
A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding...
Moderate
Unreviewed
CVE-2026-93562
was published
Sep 18, 2026
A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this...
Moderate
Unreviewed
CVE-2026-93574
was published
Sep 18, 2026
vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output...
Moderate
Unreviewed
CVE-2026-93840
was published
Sep 18, 2026
vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel...
Moderate
Unreviewed
CVE-2026-93841
was published
Sep 18, 2026
Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function...
Moderate
Unreviewed
CVE-2026-93869
was published
Sep 18, 2026
Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:...
Moderate
Unreviewed
CVE-2026-93871
was published
Sep 18, 2026
Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler...
Moderate
Unreviewed
CVE-2026-93873
was published
Sep 18, 2026
Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler,...
Moderate
Unreviewed
CVE-2026-93870
was published
Sep 18, 2026
A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition...
Moderate
Unreviewed
CVE-2026-91205
was published
Sep 18, 2026
A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by...
Moderate
Unreviewed
CVE-2026-91202
was published
Sep 18, 2026
A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing...
Moderate
Unreviewed
CVE-2026-91203
was published
Sep 18, 2026
IBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands...
Moderate
Unreviewed
CVE-2026-81623
was published
Sep 18, 2026
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute...
Moderate
Unreviewed
CVE-2026-82890
was published
Sep 18, 2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP...
Moderate
Unreviewed
CVE-2026-11722
was published
Sep 18, 2026
IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in...
Moderate
Unreviewed
CVE-2026-11711
was published
Sep 18, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security...
Moderate
Unreviewed
CVE-2026-18869
was published
Sep 18, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to...
Moderate
Unreviewed
CVE-2026-17262
was published
Sep 18, 2026
IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due...
Moderate
Unreviewed
CVE-2026-11710
was published
Sep 18, 2026
IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2026-11540
was published
Sep 18, 2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a...
Moderate
Unreviewed
CVE-2026-11549
was published
Sep 18, 2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP...
Moderate
Unreviewed
CVE-2026-11548
was published
Sep 18, 2026
IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass...
Moderate
Unreviewed
CVE-2026-11539
was published
Sep 18, 2026
A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the...
Moderate
Unreviewed
CVE-2026-92747
was published
Sep 18, 2026
A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose...
Moderate
Unreviewed
CVE-2026-92768
was published
Sep 18, 2026
ProTip!
Advisories are also available from the
GraphQL API