GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
4,171 advisories
Filter by severity
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webclient...
High
Unreviewed
CVE-2026-83276
was published
Sep 15, 2026
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver...
High
Unreviewed
CVE-2026-83280
was published
Sep 15, 2026
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server...
High
Unreviewed
CVE-2026-83222
was published
Sep 15, 2026
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server...
High
Unreviewed
CVE-2026-83225
was published
Sep 15, 2026
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server...
High
Unreviewed
CVE-2026-83228
was published
Sep 15, 2026
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server...
High
Unreviewed
CVE-2026-83183
was published
Sep 15, 2026
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated...
Moderate
Unreviewed
CVE-2026-76696
was published
Sep 15, 2026
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated...
High
Unreviewed
CVE-2026-76693
was published
Sep 15, 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
High
Unreviewed
CVE-2026-73960
was published
Sep 15, 2026
emp3r0r has an unauthenticated HTTP Polling DoS
High
CVE-2026-61554
was published
for
github.com/jm33-m0/emp3r0r/core
(Go)
Sep 15, 2026
Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZE
High
CVE-2026-88975
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s Ember HTTP/2 has an unbounded outbound frame queue
High
CVE-2026-69213
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s: DigestAuth nonce map grows unbounded
High
CVE-2026-69208
was published
for
org.http4s:http4s-ember-server_2.12
(Maven)
Sep 15, 2026
Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS
High
CVE-2026-69203
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s Ember HTTP/2: unbounded inbound body buffering
High
CVE-2026-69202
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to...
High
Unreviewed
CVE-2026-11926
was published
Sep 15, 2026
This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1,...
High
Unreviewed
CVE-2026-21588
was published
Sep 15, 2026
vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2...
High
Unreviewed
CVE-2026-91969
was published
Sep 15, 2026
Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload...
High
Unreviewed
CVE-2026-91971
was published
Sep 15, 2026
Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated...
High
Unreviewed
CVE-2026-91979
was published
Sep 15, 2026
Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in...
High
Unreviewed
CVE-2026-91941
was published
Sep 15, 2026
Affected versions of MISP do not consistently apply the existing authentication-failure logging...
Moderate
Unreviewed
CVE-2026-92003
was published
Sep 15, 2026
A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of...
Low
Unreviewed
CVE-2026-90878
was published
Sep 15, 2026
IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of...
Moderate
Unreviewed
CVE-2026-12759
was published
Sep 15, 2026
A resource exhaustion issue was addressed with improved input validation. This issue is fixed in...
High
Unreviewed
CVE-2026-84553
was published
Sep 14, 2026
ProTip!
Advisories are also available from the
GraphQL API