GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,967
Maven
5,000+
npm
5,000+
NuGet
973
pip
5,000+
Pub
13
RubyGems
1,064
Rust
1,387
Swift
56
Unreviewed advisories
All unreviewed
5,000+
15 advisories
Filter by severity
Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a...
High
Unreviewed
CVE-2026-46419
was published
May 14, 2026
mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.
Low
Unreviewed
CVE-2026-43863
was published
May 4, 2026
uutils coreutils has an Incorrect Check of Function Return Value
Moderate
CVE-2026-35340
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils incorrectly handles exit codes when processing multiple files
Moderate
CVE-2026-35339
was published
for
coreutils
(Rust)
Apr 22, 2026
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value...
High
Unreviewed
CVE-2026-35091
was published
Apr 1, 2026
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as ...
Moderate
Unreviewed
CVE-2025-54090
was published
Jul 23, 2025
Windows Hyper-V Denial of Service Vulnerability
High
Unreviewed
CVE-2024-43521
was published
Oct 8, 2024
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not...
High
Unreviewed
CVE-2024-36985
was published
Jul 1, 2024
Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is...
High
Unreviewed
CVE-2024-1622
was published
Feb 26, 2024
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary...
Critical
Unreviewed
CVE-2023-52040
was published
Jan 24, 2024
User authentication with username and password credentials is ineffective in OpenText (Micro...
Critical
Unreviewed
CVE-2023-4501
was published
Sep 12, 2023
Arbitrary file read in Citrix ADC and Citrix Gateway?
High
Unreviewed
CVE-2023-24487
was published
Jul 10, 2023
ink! vulnerable to incorrect decoding of storage value when using `DelegateCall`
Moderate
CVE-2023-34449
was published
for
ink
(Rust)
Jun 14, 2023
Potential Captcha Validate Bypass in flask-session-captcha
Moderate
CVE-2022-24880
was published
for
flask-session-captcha
(pip)
Apr 26, 2022
keycloak-connect and keycloak-js improperly handle invalid tokens
Critical
CVE-2017-7474
was published
for
keycloak-connect
(npm)
Nov 15, 2017
ProTip!
Advisories are also available from the
GraphQL API