GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
177 advisories
Filter by severity
There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is...
High
Unreviewed
CVE-2026-59284
was published
Aug 27, 2026
Spring Data REST does not guard identifier (@Id) and version (@Version) properties against...
High
Unreviewed
CVE-2026-47849
was published
Aug 27, 2026
Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root...
Moderate
Unreviewed
CVE-2026-47850
was published
Aug 27, 2026
The frontend management plugin attributed a newly created event to the submitting user's...
High
Unreviewed
CVE-2026-77144
was published
Aug 25, 2026
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an...
High
Unreviewed
CVE-2026-78416
was published
Aug 24, 2026
Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly...
High
Unreviewed
CVE-2026-49428
was published
Aug 19, 2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the...
Moderate
Unreviewed
CVE-2026-72655
was published
Aug 13, 2026
A flaw was found in the `search-v2-operator` component. A user with specific administrative...
High
Unreviewed
CVE-2026-71473
was published
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security...
High
Unreviewed
CVE-2026-17095
was published
Aug 12, 2026
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an...
High
Unreviewed
CVE-2026-72778
was published
Aug 11, 2026
A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a...
High
Unreviewed
CVE-2026-18617
was published
Aug 10, 2026
Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user...
Moderate
Unreviewed
CVE-2026-17598
was published
Aug 7, 2026
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
High
GHSA-265m-7826-wjqm
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
High
CVE-2026-69258
was published
for
flowise
(npm)
Aug 4, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19...
High
Unreviewed
CVE-2026-12436
was published
Jul 29, 2026
jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy
Moderate
CVE-2026-59888
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jul 21, 2026
rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated...
Moderate
Unreviewed
CVE-2026-63102
was published
Jul 20, 2026
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment...
High
Unreviewed
CVE-2026-58477
was published
Jul 14, 2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in...
Moderate
Unreviewed
CVE-2026-15083
was published
Jul 11, 2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in...
Moderate
Unreviewed
CVE-2026-55804
was published
Jul 11, 2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in...
Moderate
Unreviewed
CVE-2026-55803
was published
Jul 11, 2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in...
Critical
Unreviewed
CVE-2026-55809
was published
Jul 11, 2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in...
Critical
Unreviewed
CVE-2026-55810
was published
Jul 11, 2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in...
High
Unreviewed
CVE-2026-13244
was published
Jul 11, 2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in...
Critical
Unreviewed
CVE-2026-12535
was published
Jul 11, 2026
ProTip!
Advisories are also available from the
GraphQL API