GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
63 advisories
Filter by severity
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
Low
GHSA-gx4c-2hqx-cw2r
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
CVE-2026-48978
was published
for
oras.land/oras-go
(Go)
Jul 1, 2026
Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
Low
CVE-2026-7666
was published
for
django
(pip)
Jun 3, 2026
STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to...
Low
Unreviewed
CVE-2026-25608
was published
May 26, 2026
HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where...
Low
Unreviewed
CVE-2025-59852
was published
May 6, 2026
The PaperCut NG/MF (specifically, the embedded application for Konica Minolta devices) is...
Low
Unreviewed
CVE-2026-5115
was published
Mar 31, 2026
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could...
Low
Unreviewed
CVE-2025-13718
was published
Mar 13, 2026
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.
The...
Low
Unreviewed
CVE-2025-66604
was published
Feb 9, 2026
Under certain circumstances, attacker can capture the network key, read or write encrypted...
Low
Unreviewed
CVE-2025-61738
was published
Dec 22, 2025
Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution...
Low
Unreviewed
CVE-2025-63292
was published
Nov 17, 2025
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits...
Low
Unreviewed
CVE-2025-62643
was published
Oct 17, 2025
A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. This affects an unknown function...
Low
Unreviewed
CVE-2025-11640
was published
Oct 12, 2025
github.com/go-acme/lego/v4/acme/api does not enforce HTTPS
Low
CVE-2025-54799
was published
for
github.com/go-acme/lego
(Go)
Aug 6, 2025
HCL IEM is affected by a password in cleartext vulnerability. Sensitive information is...
Low
Unreviewed
CVE-2025-0252
was published
Jul 25, 2025
HCL IEM is affected by an authorization token sent in cookie vulnerability. A token used for...
Low
Unreviewed
CVE-2025-0250
was published
Jul 25, 2025
A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels...
Low
Unreviewed
CVE-2025-53861
was published
Jul 11, 2025
An improper access control vulnerability in the Endpoint Traffic Policy Enforcement https://docs...
Low
Unreviewed
CVE-2025-4227
was published
Jun 13, 2025
IBM InfoSphere Information Server 11.7 DataStage Flow Designer
transmits sensitive information...
Low
Unreviewed
CVE-2025-25046
was published
Apr 24, 2025
A vulnerability classified as problematic has been found in Consumer Comanda Mobile up to 14.9.3...
Low
Unreviewed
CVE-2025-3329
was published
Apr 7, 2025
HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. ...
Low
Unreviewed
CVE-2024-42181
was published
Jan 13, 2025
iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive...
Low
Unreviewed
CVE-2024-11946
was published
Dec 30, 2024
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote...
Low
Unreviewed
CVE-2024-49820
was published
Dec 17, 2024
Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information...
Low
Unreviewed
CVE-2024-47577
was published
Dec 10, 2024
Moodle authorization headers preserved between "emulated redirects"
Low
CVE-2024-43432
was published
for
moodle/moodle
(Composer)
Nov 11, 2024
A bug in query analysis of certain complex self-referential $lookup subpipelines may result in...
Low
Unreviewed
CVE-2024-8013
was published
Oct 28, 2024
ProTip!
Advisories are also available from the
GraphQL API