GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,406
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,124
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
132,121 advisories
Filter by severity
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS...
High
Unreviewed
CVE-2026-34791
was published
Apr 2, 2026
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS...
High
Unreviewed
CVE-2026-34797
was published
Apr 2, 2026
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS...
High
Unreviewed
CVE-2026-34793
was published
Apr 2, 2026
In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low...
High
Unreviewed
CVE-2026-3692
was published
Apr 2, 2026
A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an...
High
Unreviewed
CVE-2026-2737
was published
Apr 2, 2026
SzafirHost downloads necessary files in the context of the initiating web page. When called,...
High
Unreviewed
CVE-2026-26928
was published
Apr 2, 2026
Keycloak: Application-Level DoS via Scope Processing
High
CVE-2026-4634
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 2, 2026
Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants
High
CVE-2026-4636
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 2, 2026
Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw
High
CVE-2026-4282
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 2, 2026
Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint
High
CVE-2026-3872
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 2, 2026
In the Linux kernel, the following vulnerability has been resolved:
futex: Fix UaF between...
High
Unreviewed
CVE-2026-23415
was published
Apr 2, 2026
In the Linux kernel, the following vulnerability has been resolved:
netfilter: bpf: defer hook...
High
Unreviewed
CVE-2026-23412
was published
Apr 2, 2026
In the Linux kernel, the following vulnerability has been resolved:
clsact: Fix use-after-free...
High
Unreviewed
CVE-2026-23413
was published
Apr 2, 2026
An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection...
High
Unreviewed
CVE-2026-33616
was published
Apr 2, 2026
Due to the improper neutralisation of special elements used in an OS command, a remote attacker...
High
Unreviewed
CVE-2026-33613
was published
Apr 2, 2026
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in...
High
Unreviewed
CVE-2026-33614
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner...
High
Unreviewed
CVE-2026-29143
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA...
High
Unreviewed
CVE-2026-29139
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker...
High
Unreviewed
CVE-2026-29140
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject...
High
Unreviewed
CVE-2026-29144
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject...
High
Unreviewed
CVE-2026-29141
was published
Apr 2, 2026
Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows local apps to...
High
Unreviewed
CVE-2026-0634
was published
Apr 2, 2026
The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions...
High
Unreviewed
CVE-2026-0686
was published
Apr 2, 2026
The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up...
High
Unreviewed
CVE-2026-5032
was published
Apr 2, 2026
The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file,...
High
Unreviewed
CVE-2026-1540
was published
Apr 2, 2026
ProTip!
Advisories are also available from the
GraphQL API