GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,826
Maven
5,000+
npm
5,000+
NuGet
942
pip
5,000+
Pub
13
RubyGems
1,060
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
302,747 advisories
Filter by severity
An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker...
Unknown
Unreviewed
CVE-2026-39079
was published
May 18, 2026
Dify version 1.14.1 and prior contain an authorization bypass vulnerability in the file preview...
High
Unreviewed
CVE-2026-41949
was published
May 18, 2026
Dify version 1.14.1 and prior contains an authorization bypass vulnerability that allows...
Critical
Unreviewed
CVE-2026-41947
was published
May 18, 2026
Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated...
Critical
Unreviewed
CVE-2026-41948
was published
May 18, 2026
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport...
High
Unreviewed
CVE-2026-42009
was published
May 18, 2026
Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron...
Unknown
Unreviewed
CVE-2026-26462
was published
May 18, 2026
A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the...
Moderate
Unreviewed
CVE-2026-8803
was published
May 18, 2026
Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain...
Critical
Unreviewed
CVE-2026-4320
was published
May 18, 2026
A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue...
Moderate
Unreviewed
CVE-2026-8802
was published
May 18, 2026
Dell Live Optics Windows and Personal Edition collectors contain an improper certificate...
Moderate
Unreviewed
CVE-2026-41119
was published
May 18, 2026
Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and...
High
Unreviewed
CVE-2026-0983
was published
May 18, 2026
SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and...
Critical
Unreviewed
CVE-2026-7301
was published
May 18, 2026
SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when...
Critical
Unreviewed
CVE-2026-7304
was published
May 18, 2026
SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal...
Critical
Unreviewed
CVE-2026-7302
was published
May 18, 2026
Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections.
The values from...
Unknown
Unreviewed
CVE-2026-8788
was published
May 18, 2026
Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for...
Moderate
Unreviewed
CVE-2026-3117
was published
May 18, 2026
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize...
High
Unreviewed
CVE-2026-6346
was published
May 18, 2026
Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI...
Moderate
Unreviewed
CVE-2026-5163
was published
May 18, 2026
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check public...
Moderate
Unreviewed
CVE-2026-6343
was published
May 18, 2026
Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading...
Moderate
Unreviewed
CVE-2026-3471
was published
May 18, 2026
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if {{team_id}} was being...
Low
Unreviewed
CVE-2026-4286
was published
May 18, 2026
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent...
Moderate
Unreviewed
CVE-2026-6345
was published
May 18, 2026
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash...
Moderate
Unreviewed
CVE-2026-28732
was published
May 18, 2026
Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to have API-level checks on...
Moderate
Unreviewed
CVE-2026-6341
was published
May 18, 2026
Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from...
Low
Unreviewed
CVE-2026-4643
was published
May 18, 2026
ProTip!
Advisories are also available from the
GraphQL API