GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
145,863 advisories
Filter by severity
A heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c in HDF5 before 2.2.0 lets a...
High
Unreviewed
CVE-2026-106547
was published
Oct 6, 2026
Improper input validation in the AMD ROCm Communication Collectives Library (RCCL) could allow a...
High
Unreviewed
CVE-2026-43598
was published
Oct 6, 2026
Authorization bypass through a user-controlled key in the optional Amazon Q Business Lambda hook...
High
Unreviewed
CVE-2026-105811
was published
Oct 6, 2026
Symbolic name not mapping to correct object vulnerability in Apache Commons.
BCEL caches...
High
Unreviewed
CVE-2026-94114
was published
Oct 6, 2026
A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document,...
High
Unreviewed
CVE-2026-101258
was published
Oct 6, 2026
A missing integrity verification vulnerability in the Windows client software for ClearPass...
High
Unreviewed
CVE-2026-79807
was published
Oct 6, 2026
A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a...
High
Unreviewed
CVE-2026-106062
was published
Oct 6, 2026
Remote code execution vulnerabilities exist in the affected interface of HPE Networking ClearPass...
High
Unreviewed
CVE-2026-79810
was published
Oct 6, 2026
An authenticated path traversal vulnerability exists in the command line interface of ClearPass...
High
Unreviewed
CVE-2026-79800
was published
Oct 6, 2026
A SQL injection vulnerability in the API of ClearPass Policy Manager could allow a remote...
High
Unreviewed
CVE-2026-79811
was published
Oct 6, 2026
A command injection vulnerability exists in the client software of ClearPass Policy Manager....
High
Unreviewed
CVE-2026-79802
was published
Oct 6, 2026
An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy...
High
Unreviewed
CVE-2026-79809
was published
Oct 6, 2026
A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could...
High
Unreviewed
CVE-2026-79806
was published
Oct 6, 2026
A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager....
High
Unreviewed
CVE-2026-79808
was published
Oct 6, 2026
A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful...
High
Unreviewed
CVE-2026-79803
was published
Oct 6, 2026
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an...
High
Unreviewed
CVE-2026-79799
was published
Oct 6, 2026
An improper access control vulnerability exists in the Android client application for HPE...
High
Unreviewed
CVE-2026-79797
was published
Oct 6, 2026
A privilege escalation vulnerability exists in the API of AOS-S. Successful exploitation could...
High
Unreviewed
CVE-2026-76748
was published
Oct 6, 2026
Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to...
High
Unreviewed
CVE-2026-103009
was published
Oct 6, 2026
Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a...
High
Unreviewed
CVE-2026-103007
was published
Oct 6, 2026
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant...
High
Unreviewed
CVE-2026-102406
was published
Oct 6, 2026
On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an...
High
Unreviewed
CVE-2026-102163
was published
Oct 6, 2026
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless...
High
Unreviewed
CVE-2026-102168
was published
Oct 6, 2026
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless...
High
Unreviewed
CVE-2026-102169
was published
Oct 6, 2026
On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the...
High
Unreviewed
CVE-2026-102165
was published
Oct 6, 2026
ProTip!
Advisories are also available from the
GraphQL API