GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,722
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,568
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
2,481 advisories
Filter by severity
GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without...
Critical
Unreviewed
CVE-2026-88285
was published
Sep 10, 2026
An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node...
Unknown
Unreviewed
CVE-2026-49363
was published
Sep 10, 2026
A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a...
Unknown
Unreviewed
CVE-2026-67593
was published
Sep 10, 2026
An unauthenticated network-adjacent attacker can leverage discovery to capture cluster...
Unknown
Unreviewed
CVE-2026-49364
was published
Sep 10, 2026
An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an...
Unknown
Unreviewed
CVE-2026-57967
was published
Sep 10, 2026
An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol,...
Unknown
Unreviewed
CVE-2026-49362
was published
Sep 10, 2026
@yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run
High
CVE-2026-59160
was published
for
@yeger/turbo-graph
(npm)
Sep 9, 2026
After spoofing the device and obtaining one user confirmation, an attacker may be able to cause...
High
Unreviewed
CVE-2026-77974
was published
Sep 9, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
Moderate
Unreviewed
CVE-2026-79961
was published
Sep 9, 2026
Missing authentication for critical function vulnerability in Yordam Informatics Technology...
Moderate
Unreviewed
CVE-2026-11838
was published
Sep 9, 2026
Windows ML CLI: CORS misconfig enables localhost RCE
High
CVE-2026-84452
was published
for
winml-cli
(pip)
Sep 8, 2026
Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an...
Moderate
Unreviewed
CVE-2026-83991
was published
Sep 8, 2026
Missing authentication for critical function in Windows Autopilot allows an authorized attacker...
Moderate
Unreviewed
CVE-2026-73004
was published
Sep 8, 2026
Missing authentication for critical function in Windows Internet Connection Sharing (ICS) allows...
Moderate
Unreviewed
CVE-2026-72964
was published
Sep 8, 2026
Missing authentication for critical function in Windows Modern Device Management (MDM) allows an...
Moderate
Unreviewed
CVE-2026-69674
was published
Sep 8, 2026
Missing authentication for critical function in Microsoft Windows Search Component allows an...
Moderate
Unreviewed
CVE-2026-69554
was published
Sep 8, 2026
Missing authentication for critical function in Windows Shell allows an authorized attacker to...
High
Unreviewed
CVE-2026-69528
was published
Sep 8, 2026
Missing authentication for critical function in Windows DHCP Server allows an authorized attacker...
Moderate
Unreviewed
CVE-2026-69415
was published
Sep 8, 2026
Missing authentication for critical function in Windows Power Dependency Coordinator allows an...
Moderate
Unreviewed
CVE-2026-69321
was published
Sep 8, 2026
AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json...
High
Unreviewed
CVE-2026-86728
was published
Sep 8, 2026
AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json...
High
Unreviewed
CVE-2026-86727
was published
Sep 8, 2026
Private Metrics Server contained a missing authentication condition affecting metrics upload...
High
Unreviewed
CVE-2026-77097
was published
Sep 8, 2026
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is...
Critical
Unreviewed
CVE-2026-62645
was published
Sep 8, 2026
Missing authentication for a critical function in ASUS Control Center Express Agent allows an...
High
Unreviewed
CVE-2026-19397
was published
Sep 8, 2026
knowns versions before 0.30.0 serve the management API without authentication on all network...
Critical
Unreviewed
CVE-2026-86543
was published
Sep 8, 2026
ProTip!
Advisories are also available from the
GraphQL API