GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,430
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,680
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
112,392 advisories
Filter by severity
Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated...
High
Unreviewed
CVE-2026-5301
was published
Apr 8, 2026
In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two...
High
Unreviewed
CVE-2026-5795
was published
Apr 8, 2026
Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4...
High
Unreviewed
CVE-2026-28261
was published
Apr 8, 2026
Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers...
High
Unreviewed
CVE-2026-5208
was published
Apr 8, 2026
WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the ...
High
Unreviewed
CVE-2026-3396
was published
Apr 8, 2026
The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to...
High
Unreviewed
CVE-2026-3243
was published
Apr 8, 2026
An exposed IOCTL with an insufficient access control vulnerability has been identified in the...
High
Unreviewed
CVE-2026-4483
was published
Apr 8, 2026
The Gerador de Certificados – DevApps plugin for WordPress is vulnerable to arbitrary file...
High
Unreviewed
CVE-2026-4808
was published
Apr 8, 2026
SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is...
High
Unreviewed
CVE-2026-24913
was published
Apr 8, 2026
ASDA-Soft Stack-based Buffer Overflow Vulnerability
High
Unreviewed
CVE-2026-5726
was published
Apr 8, 2026
The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for...
High
Unreviewed
CVE-2026-3499
was published
Apr 8, 2026
IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute...
High
Unreviewed
CVE-2026-3357
was published
Apr 8, 2026
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores sensitive information in log files that...
High
Unreviewed
CVE-2026-4788
was published
Apr 8, 2026
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container...
High
Unreviewed
CVE-2026-1343
was published
Apr 8, 2026
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container...
High
Unreviewed
CVE-2026-1342
was published
Apr 8, 2026
Improper removal of sensitive information before storage or transfer vulnerability in The...
High
Unreviewed
CVE-2026-39937
was published
Apr 8, 2026
Issue summary: Applications using RSASVE key encapsulation to establish
a secret encryption key...
High
Unreviewed
CVE-2026-31790
was published
Apr 8, 2026
There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted...
High
Unreviewed
CVE-2026-32860
was published
Apr 7, 2026
The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures...
High
Unreviewed
CVE-2025-14859
was published
Apr 7, 2026
There is a memory corruption vulnerability due to an out-of-bounds read in mgcore_SH_25_3...
High
Unreviewed
CVE-2026-32864
was published
Apr 7, 2026
There is a memory corruption vulnerability due to an out-of-bounds write in ResFileFactory:...
High
Unreviewed
CVE-2026-32862
was published
Apr 7, 2026
There is a memory corruption vulnerability due to an out-of-bounds read in...
High
Unreviewed
CVE-2026-32863
was published
Apr 7, 2026
There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted...
High
Unreviewed
CVE-2026-32861
was published
Apr 7, 2026
NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted...
High
Unreviewed
CVE-2026-24156
was published
Apr 7, 2026
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server...
High
Unreviewed
CVE-2026-24173
was published
Apr 7, 2026
ProTip!
Advisories are also available from the
GraphQL API