GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,702 advisories
Filter by severity
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
Moderate
CVE-2026-54712
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function...
Moderate
Unreviewed
CVE-2026-17501
was published
Jul 27, 2026
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7...
Moderate
Unreviewed
CVE-2026-43768
was published
Jul 27, 2026
A logic issue existed resulting in memory corruption. This was addressed with improved state...
Moderate
Unreviewed
CVE-2026-28932
was published
Jul 27, 2026
hermes-agent has an Uncontrolled Resource Consumption issue
Moderate
CVE-2026-10224
was published
for
hermes-agent
(pip)
Jun 1, 2026
This issue was addressed through improved state management. This issue is fixed in Safari 26.6,...
Moderate
Unreviewed
CVE-2026-43804
was published
Jul 27, 2026
A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in...
Moderate
Unreviewed
CVE-2026-43806
was published
Jul 27, 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS...
Moderate
Unreviewed
CVE-2026-64724
was published
Jul 27, 2026
An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE...
Moderate
Unreviewed
CVE-2026-42006
was published
May 12, 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and...
Moderate
Unreviewed
CVE-2026-43653
was published
May 11, 2026
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON...
Moderate
Unreviewed
CVE-2026-60718
was published
Jul 22, 2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a...
Moderate
Unreviewed
CVE-2026-38763
was published
Jul 23, 2026
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server:...
Moderate
Unreviewed
CVE-2026-60747
was published
Jul 22, 2026
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
Moderate
CVE-2026-55497
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Vulnerability in Oracle GoldenGate (component: Receiver Service Executable). Supported versions...
Moderate
Unreviewed
CVE-2026-60399
was published
Jul 22, 2026
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database ...
Moderate
Unreviewed
CVE-2026-60410
was published
Jul 22, 2026
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database ...
Moderate
Unreviewed
CVE-2026-60403
was published
Jul 22, 2026
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database ...
Moderate
Unreviewed
CVE-2026-60411
was published
Jul 22, 2026
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
Moderate
GHSA-r292-9mhp-454m
was published
for
tar
(npm)
Jul 24, 2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The...
Moderate
Unreviewed
CVE-2026-61052
was published
Jul 22, 2026
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle...
Moderate
Unreviewed
CVE-2026-61070
was published
Jul 22, 2026
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database ...
Moderate
Unreviewed
CVE-2026-60404
was published
Jul 22, 2026
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
Moderate
CVE-2026-55595
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
Moderate
CVE-2026-55594
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server:...
Moderate
Unreviewed
CVE-2026-60324
was published
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API