GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,113 advisories
Filter by severity
Windows Partition Management Driver Elevation of Privilege Vulnerability
Moderate
Unreviewed
CVE-2021-34493
was published
May 24, 2022
A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user...
Moderate
Unreviewed
CVE-2026-16071
was published
Aug 5, 2026
Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate...
Moderate
Unreviewed
CVE-2026-70443
was published
Aug 5, 2026
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an...
Moderate
Unreviewed
CVE-2026-20308
was published
Aug 5, 2026
Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Install /...
Moderate
Unreviewed
CVE-2026-61064
was published
Jul 22, 2026
Improper access control in the IRP_MJ_WRITE command interface in
Wellbia XIGNCODE3 xhunter2.sys,...
Moderate
Unreviewed
CVE-2026-15430
was published
Aug 3, 2026
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)
Moderate
CVE-2026-65835
was published
for
github.com/projectcapsule/capsule
(Go)
Jul 31, 2026
An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed...
Moderate
Unreviewed
CVE-2023-6507
was published
Dec 8, 2023
In multiple locations, there is a possible tapjacking due to a logic error in the code. This...
Moderate
Unreviewed
CVE-2026-0009
was published
Jun 2, 2026
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database ...
Moderate
Unreviewed
CVE-2026-60406
was published
Jul 22, 2026
Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite ...
Moderate
Unreviewed
CVE-2026-60957
was published
Jul 22, 2026
Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component:...
Moderate
Unreviewed
CVE-2026-60938
was published
Jul 22, 2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component:...
Moderate
Unreviewed
CVE-2026-60342
was published
Jul 22, 2026
A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user...
Moderate
Unreviewed
CVE-2026-16743
was published
Jul 24, 2026
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component:...
Moderate
Unreviewed
CVE-2026-61013
was published
Jul 22, 2026
Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component:...
Moderate
Unreviewed
CVE-2026-61023
was published
Jul 22, 2026
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component...
Moderate
Unreviewed
CVE-2026-61176
was published
Jul 22, 2026
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle...
Moderate
Unreviewed
CVE-2026-61182
was published
Jul 22, 2026
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server:...
Moderate
Unreviewed
CVE-2026-60183
was published
Jul 22, 2026
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). ...
Moderate
Unreviewed
CVE-2026-60162
was published
Jul 22, 2026
Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite ...
Moderate
Unreviewed
CVE-2026-62474
was published
Jul 22, 2026
There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect...
Moderate
Unreviewed
CVE-2026-57599
was published
Jul 22, 2026
A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task...
Moderate
Unreviewed
CVE-2026-15380
was published
Jul 17, 2026
The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard...
Moderate
Unreviewed
CVE-2026-15379
was published
Jul 17, 2026
Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
Moderate
CVE-2026-54319
was published
for
github.com/daytonaio/daytona
(Go)
Jun 18, 2026
ProTip!
Advisories are also available from the
GraphQL API