GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
734 advisories
Filter by severity
A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior...
High
Unreviewed
CVE-2026-75946
was published
Aug 21, 2026
Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0...
Unknown
Unreviewed
CVE-2026-68745
was published
Aug 21, 2026
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized...
Critical
Unreviewed
CVE-2026-62834
was published
Aug 21, 2026
The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an...
Moderate
Unreviewed
CVE-2026-72861
was published
Aug 20, 2026
node-opcua missing nonce verification in UserNameIdentityToken authentication
High
CVE-2026-54155
was published
for
node-opcua
(npm)
Aug 20, 2026
libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain...
High
Unreviewed
CVE-2026-76234
was published
Aug 19, 2026
After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to...
Unknown
Unreviewed
CVE-2026-58085
was published
Aug 19, 2026
Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System...
High
Unreviewed
CVE-2025-9210
was published
Aug 18, 2026
Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1...
Critical
Unreviewed
CVE-2021-43716
was published
Aug 18, 2026
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
High
GHSA-fhgh-wq4q-r37x
was published
for
gitlab.com/uniget-org/cli
(Go)
Aug 17, 2026
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py...
Critical
Unreviewed
CVE-2026-74901
was published
Aug 17, 2026
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that...
Critical
Unreviewed
CVE-2026-74876
was published
Aug 17, 2026
A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an...
Moderate
Unreviewed
CVE-2026-74244
was published
Aug 15, 2026
PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution...
High
Unreviewed
CVE-2026-19910
was published
Aug 14, 2026
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
Critical
Unreviewed
CVE-2026-28148
was published
Aug 13, 2026
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551...
High
Unreviewed
CVE-2026-12263
was published
Aug 13, 2026
A holder of a valid integration credential may impersonate other users under specific conditions.
High
Unreviewed
CVE-2026-68759
was published
Aug 12, 2026
A user with access to a valid SAML response may impersonate another user under specific conditions.
High
Unreviewed
CVE-2026-68757
was published
Aug 12, 2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption...
Critical
Unreviewed
CVE-2025-59324
was published
Aug 12, 2026
In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate...
High
Unreviewed
CVE-2025-59327
was published
Aug 12, 2026
Improper verification of cryptographic signature in Windows Schannel allows an unauthorized...
Moderate
Unreviewed
CVE-2026-62757
was published
Aug 11, 2026
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero...
High
Unreviewed
CVE-2026-15556
was published
Aug 11, 2026
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept...
Critical
Unreviewed
CVE-2026-10579
was published
Aug 11, 2026
SAP Approuter does not consistently enforce integrity verification on certain session-related...
Moderate
Unreviewed
CVE-2026-66776
was published
Aug 11, 2026
Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of...
High
Unreviewed
CVE-2026-10754
was published
Aug 10, 2026
ProTip!
Advisories are also available from the
GraphQL API