GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
381,615 advisories
Filter by severity
A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration...
Critical
Unreviewed
CVE-2026-86131
was published
Sep 30, 2026
In the Linux kernel, the following vulnerability has been resolved:
cachefiles: Fix error return...
Moderate
Unreviewed
CVE-2026-64040
was published
Jul 19, 2026
A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature...
High
Unreviewed
CVE-2026-86128
was published
Sep 30, 2026
Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that...
Critical
Unreviewed
CVE-2026-79796
was published
Oct 6, 2026
A SQL injection vulnerability in the web-based management interface of ClearPass Policy Manager...
Critical
Unreviewed
CVE-2026-79794
was published
Oct 6, 2026
In sshd in OpenSSH before 10.6, credentials can incorrectly persist after failure of a...
Low
Unreviewed
CVE-2026-106553
was published
Oct 6, 2026
A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could...
High
Unreviewed
CVE-2026-79806
was published
Oct 6, 2026
In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used even though this is...
Low
Unreviewed
CVE-2026-106582
was published
Oct 6, 2026
Authorization bypass through a user-controlled key in the optional Amazon Q Business Lambda hook...
High
Unreviewed
CVE-2026-105811
was published
Oct 6, 2026
In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be...
Low
Unreviewed
CVE-2026-106586
was published
Oct 6, 2026
A flaw was found in SSSD (System Security Services Daemon). When Identity Provider (IdP)...
Moderate
Unreviewed
CVE-2026-104046
was published
Oct 6, 2026
A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager....
High
Unreviewed
CVE-2026-79808
was published
Oct 6, 2026
Symbolic name not mapping to correct object vulnerability in Apache Commons.
BCEL caches...
High
Unreviewed
CVE-2026-94114
was published
Oct 6, 2026
A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document,...
High
Unreviewed
CVE-2026-101258
was published
Oct 6, 2026
Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service...
Unknown
Unreviewed
CVE-2026-106550
was published
Oct 6, 2026
Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking...
Critical
Unreviewed
CVE-2026-76750
was published
Oct 6, 2026
A missing integrity verification vulnerability in the Windows client software for ClearPass...
High
Unreviewed
CVE-2026-79807
was published
Oct 6, 2026
A sensitive information disclosure vulnerability exists in the client software of HPE Networking...
Moderate
Unreviewed
CVE-2026-79817
was published
Oct 6, 2026
A heap-based buffer over-read in H5Z__filter_scaleoffset() in src/H5Zscaleoffset.c in HDF5...
Moderate
Unreviewed
CVE-2026-19029
was published
Oct 6, 2026
A heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c in HDF5 before 2.2.0 lets a...
High
Unreviewed
CVE-2026-106547
was published
Oct 6, 2026
In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because...
Low
Unreviewed
CVE-2026-106584
was published
Oct 6, 2026
In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length...
Moderate
Unreviewed
CVE-2026-106585
was published
Oct 6, 2026
In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be...
Low
Unreviewed
CVE-2026-106555
was published
Oct 6, 2026
A vulnerability in an API interface of ClearPass Policy Manager could allow an unauthenticated...
Moderate
Unreviewed
CVE-2026-79818
was published
Oct 6, 2026
Improper input validation in the AMD ROCm Communication Collectives Library (RCCL) could allow a...
High
Unreviewed
CVE-2026-43598
was published
Oct 6, 2026
ProTip!
Advisories are also available from the
GraphQL API