GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
25 advisories
Filter by severity
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack...
Moderate
Unreviewed
CVE-2026-55655
was published
Jun 23, 2026
Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement...
Moderate
Unreviewed
CVE-2026-63226
was published
Jul 23, 2026
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper...
Moderate
Unreviewed
CVE-2026-57028
was published
Jul 10, 2026
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper...
Moderate
Unreviewed
CVE-2026-33803
was published
Jul 10, 2026
Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS...
Moderate
Unreviewed
CVE-2026-12039
was published
Jun 18, 2026
IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound...
Moderate
Unreviewed
CVE-2025-36145
was published
May 26, 2026
Route Services can be leveraged to send app traffic to network destinations outside of an app's...
Moderate
Unreviewed
CVE-2026-22726
was published
May 1, 2026
IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between...
Moderate
Unreviewed
CVE-2025-36180
was published
May 1, 2026
IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due...
Moderate
Unreviewed
CVE-2025-36438
was published
Mar 25, 2026
This issue affects: Secomea GateManager All versions prior to 9.6. Improper Check of host header...
Moderate
Unreviewed
CVE-2021-32004
was published
Nov 23, 2021
VMWare Workstation and Fusion contain a logic flaw in the management of network packets.
Known...
Moderate
Unreviewed
CVE-2026-22715
was published
Feb 26, 2026
NVIDIA RunAI for all platforms contains a vulnerability where a user could cause an improper...
Moderate
Unreviewed
CVE-2025-33176
was published
Nov 4, 2025
Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1...
Moderate
Unreviewed
CVE-2025-35978
was published
Jun 12, 2025
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. All packets...
Moderate
Unreviewed
CVE-2025-32886
was published
May 2, 2025
Quick Agent V3 and Quick Agent V2 contain an issue with improper restriction of communication...
Moderate
Unreviewed
CVE-2025-31144
was published
Apr 28, 2025
IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1...
Moderate
Unreviewed
CVE-2022-43916
was published
Jan 30, 2025
IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by...
Moderate
Unreviewed
CVE-2024-22315
was published
Jan 28, 2025
Sudo for Windows Spoofing Vulnerability
Moderate
Unreviewed
CVE-2024-43571
was published
Oct 8, 2024
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper...
Moderate
Unreviewed
CVE-2024-39537
was published
Jul 11, 2024
Improper restriction of communication channel to intended endpoints issue exists in Ricoh...
Moderate
Unreviewed
CVE-2024-36252
was published
Jun 19, 2024
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the...
Moderate
Unreviewed
CVE-2023-44195
was published
Oct 13, 2023
NVIDIA Jetson contains a vulnerability in CBoot, where the PCIe controller is initialized...
Moderate
Unreviewed
CVE-2023-25518
was published
Jun 23, 2023
Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea...
Moderate
Unreviewed
CVE-2022-38125
was published
Apr 19, 2023
The IP filter in ABAP Platform and SAP Web Dispatcher - versions WEBDISP 7.85, 7.89, KERNEL 7.85,...
Moderate
Unreviewed
CVE-2023-29108
was published
Apr 11, 2023
An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be...
Moderate
Unreviewed
CVE-2022-2663
was published
Sep 2, 2022
ProTip!
Advisories are also available from the
GraphQL API