GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,511
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,512
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,042 advisories
Filter by severity
A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending...
High
Unreviewed
CVE-2026-71469
was published
Aug 13, 2026
IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local...
Low
Unreviewed
CVE-2026-18096
was published
Aug 12, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19...
Moderate
Unreviewed
CVE-2026-7427
was published
Aug 12, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to...
High
Unreviewed
CVE-2026-17271
was published
Aug 12, 2026
A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0...
Moderate
Unreviewed
CVE-2026-71408
was published
Aug 12, 2026
An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication...
High
Unreviewed
CVE-2025-41770
was published
Aug 12, 2026
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized...
High
Unreviewed
CVE-2026-54113
was published
Aug 11, 2026
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and...
High
Unreviewed
CVE-2026-15561
was published
Aug 11, 2026
Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or...
Moderate
Unreviewed
CVE-2026-19517
was published
Aug 11, 2026
SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with...
Moderate
Unreviewed
CVE-2026-66761
was published
Aug 11, 2026
SAP Approuter does not sufficiently handle certain requests under specific conditions. An...
Moderate
Unreviewed
CVE-2026-58238
was published
Aug 11, 2026
A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated,...
High
Unreviewed
CVE-2026-18618
was published
Aug 10, 2026
TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in...
High
Unreviewed
CVE-2025-15682
was published
Aug 10, 2026
A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS)...
Moderate
Unreviewed
CVE-2026-12570
was published
Aug 10, 2026
Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an...
Moderate
Unreviewed
CVE-2026-19014
was published
Aug 7, 2026
Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can...
Moderate
Unreviewed
CVE-2025-71410
was published
Aug 7, 2026
Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed...
Moderate
Unreviewed
CVE-2025-71411
was published
Aug 7, 2026
Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an...
High
Unreviewed
CVE-2026-15972
was published
Aug 7, 2026
Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an...
Moderate
Unreviewed
CVE-2026-19015
was published
Aug 7, 2026
Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ...
High
Unreviewed
CVE-2026-67585
was published
Aug 7, 2026
Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to...
High
Unreviewed
CVE-2026-54225
was published
Aug 6, 2026
A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP...
High
Unreviewed
CVE-2026-18649
was published
Aug 6, 2026
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
High
CVE-2026-71321
was published
for
nuxt
(npm)
Aug 5, 2026
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
High
CVE-2026-71314
was published
for
nuxt
(npm)
Aug 5, 2026
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
Moderate
CVE-2026-71310
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
ProTip!
Advisories are also available from the
GraphQL API