GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,460
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,142
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
89 advisories
Filter by severity
Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote...
Critical
Unreviewed
CVE-2026-14151
was published
Jul 1, 2026
OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints
Moderate
CVE-2026-46448
was published
for
nova
(pip)
Jun 16, 2026
Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may...
High
Unreviewed
CVE-2026-12068
was published
Jun 13, 2026
OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read...
Moderate
Unreviewed
CVE-2026-44917
was published
Jun 4, 2026
OpenStack Ironic allows Boot Script Injection
Moderate
CVE-2026-46447
was published
for
ironic
(pip)
Jun 4, 2026
Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary...
Low
Unreviewed
CVE-2026-48847
was published
May 26, 2026
In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image...
Moderate
Unreviewed
CVE-2026-48845
was published
May 26, 2026
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking...
Moderate
Unreviewed
CVE-2026-48846
was published
May 26, 2026
Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several...
High
Unreviewed
CVE-2026-48831
was published
May 26, 2026
Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.
Low
Unreviewed
CVE-2026-44599
was published
May 7, 2026
Talos Linux has a local privilege escalation from untrusted workloads
High
GHSA-m38g-vww2-mvgx
was published
for
github.com/siderolabs/talos
(Go)
May 7, 2026
OpenStack Ironic has an Incorrect Resource Transfer Between Spheres
High
CVE-2026-42997
was published
for
ironic-python-agent
(pip)
May 5, 2026
mpGabinet is vulnerable to Remote Command Execution. An authorized user with access to the...
Moderate
Unreviewed
CVE-2026-40552
was published
Apr 28, 2026
KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to...
Moderate
Unreviewed
CVE-2026-41525
was published
Apr 28, 2026
In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert...
High
Unreviewed
CVE-2026-31431
was published
Apr 22, 2026
In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions...
Moderate
Unreviewed
CVE-2026-41030
was published
Apr 16, 2026
In udev in systemd before 260, local root execution can occur via malicious hardware devices and...
Moderate
Unreviewed
CVE-2026-40225
was published
Apr 10, 2026
In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary...
Low
Unreviewed
CVE-2026-40228
was published
Apr 10, 2026
Roundcube Webmail: Bypass of remote image blocking via SVG content (with animate attributes) in an e-mail message
Moderate
CVE-2026-35543
was published
for
roundcube/roundcubemail
(Composer)
Apr 3, 2026
Roundcube Webmail: Remote image blocking feature can be bypassed via SVG content in an e-mail message
Moderate
CVE-2026-35545
was published
for
roundcube/roundcubemail
(Composer)
Apr 3, 2026
Roundcube: Bypass of remote image blocking via crafted BODY background attribute
Moderate
CVE-2026-35542
was published
for
roundcube/roundcubemail
(Composer)
Apr 3, 2026
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
Moderate
CVE-2026-35544
was published
for
roundcube/roundcubemail
(Composer)
Apr 3, 2026
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
Moderate
CVE-2026-35540
was published
for
roundcube/roundcubemail
(Composer)
Apr 3, 2026
A low-privileged remote attacker may be able to replace the boot application of the CODESYS...
High
Unreviewed
CVE-2025-41660
was published
Mar 24, 2026
In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.
Moderate
Unreviewed
CVE-2026-33265
was published
Mar 18, 2026
ProTip!
Advisories are also available from the
GraphQL API