GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,450
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,134
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,701 advisories
Filter by severity
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS...
Moderate
Unreviewed
CVE-2026-64724
was published
Jul 27, 2026
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7...
Moderate
Unreviewed
CVE-2026-43768
was published
Jul 27, 2026
This issue was addressed through improved state management. This issue is fixed in Safari 26.6,...
Moderate
Unreviewed
CVE-2026-43804
was published
Jul 27, 2026
A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in...
Moderate
Unreviewed
CVE-2026-43806
was published
Jul 27, 2026
A logic issue existed resulting in memory corruption. This was addressed with improved state...
Moderate
Unreviewed
CVE-2026-28932
was published
Jul 27, 2026
A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function...
Moderate
Unreviewed
CVE-2026-17501
was published
Jul 27, 2026
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
Moderate
CVE-2026-55497
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
Moderate
GHSA-r292-9mhp-454m
was published
for
tar
(npm)
Jul 24, 2026
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
Moderate
CVE-2026-55595
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
Moderate
CVE-2026-55594
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
pypdf: Possible long runtimes for repeated malformed cross-reference entries
Moderate
CVE-2026-59937
was published
for
pypdf
(pip)
Jul 23, 2026
The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test)...
Moderate
Unreviewed
CVE-2026-21723
was published
Jul 23, 2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a...
Moderate
Unreviewed
CVE-2026-38763
was published
Jul 23, 2026
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
Moderate
CVE-2026-59942
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
Moderate
CVE-2026-59941
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A...
Moderate
Unreviewed
CVE-2026-45820
was published
Jul 22, 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via...
Moderate
Unreviewed
CVE-2026-63263
was published
Jul 22, 2026
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive...
Moderate
Unreviewed
CVE-2026-63260
was published
Jul 22, 2026
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive...
Moderate
Unreviewed
CVE-2026-63261
was published
Jul 22, 2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain ...
Moderate
Unreviewed
CVE-2026-61192
was published
Jul 22, 2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain ...
Moderate
Unreviewed
CVE-2026-61195
was published
Jul 22, 2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain ...
Moderate
Unreviewed
CVE-2026-61194
was published
Jul 22, 2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product...
Moderate
Unreviewed
CVE-2026-61147
was published
Jul 22, 2026
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server:...
Moderate
Unreviewed
CVE-2026-61144
was published
Jul 22, 2026
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server:...
Moderate
Unreviewed
CVE-2026-61128
was published
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API