GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
15,618 advisories
Filter by severity
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Low
GHSA-5qhf-9phg-95m2
was published
for
loofah
(RubyGems)
Jul 21, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API
Low
CVE-2026-58511
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in...
Low
Unreviewed
CVE-2026-11925
was published
Jul 21, 2026
SoupAuthManager caches proxy authentication credentials without scoping them to the proxy...
Low
Unreviewed
CVE-2026-12547
was published
Jul 21, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
Low
CVE-2026-55984
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation
Low
CVE-2026-58434
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
Low
CVE-2026-58445
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
Low
CVE-2026-58438
was published
for
gitea.dev
(Go)
Jul 21, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
Low
CVE-2026-23603
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
Low
GHSA-c2j3-45gr-mqc4
was published
for
dompurify
(npm)
Jul 21, 2026
HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to...
Low
Unreviewed
CVE-2026-56579
was published
Jul 21, 2026
HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may...
Low
Unreviewed
CVE-2026-56580
was published
Jul 21, 2026
HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account...
Low
Unreviewed
CVE-2026-56577
was published
Jul 21, 2026
HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this...
Low
Unreviewed
CVE-2026-56582
was published
Jul 21, 2026
HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit...
Low
Unreviewed
CVE-2026-56578
was published
Jul 21, 2026
HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of...
Low
Unreviewed
CVE-2026-56583
was published
Jul 21, 2026
HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of...
Low
Unreviewed
CVE-2026-56581
was published
Jul 21, 2026
A security flaw has been discovered in zsadmin2025 ZS-Admin up to...
Low
Unreviewed
CVE-2026-16451
was published
Jul 21, 2026
Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly...
Low
Unreviewed
CVE-2026-64823
was published
Jul 21, 2026
HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow...
Low
Unreviewed
CVE-2026-56585
was published
Jul 21, 2026
HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to...
Low
Unreviewed
CVE-2026-56586
was published
Jul 21, 2026
A vulnerability was determined in zsadmin2025 ZS-Admin up to...
Low
Unreviewed
CVE-2026-16449
was published
Jul 21, 2026
A vulnerability was identified in zsadmin2025 ZS-Admin up to...
Low
Unreviewed
CVE-2026-16450
was published
Jul 21, 2026
HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to...
Low
Unreviewed
CVE-2026-56584
was published
Jul 21, 2026
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW,...
Low
Unreviewed
CVE-2026-16448
was published
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API