GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,227
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,502
Pub
12
RubyGems
995
Rust
1,187
Swift
51
Unreviewed advisories
All unreviewed
5,000+
152,691 advisories
Filter by severity
NULL Pointer Dereference vulnerability in Softing Industrial Automation GmbH smartLink SW-HT ...
Moderate
Unreviewed
CVE-2025-13406
was published
Mar 17, 2026
Katello: Denial of Service and potential information disclosure via SQL injection
Moderate
CVE-2026-4324
was published
for
katello
(RubyGems)
Mar 17, 2026
Next.js: null origin can bypass Server Actions CSRF checks
Moderate
CVE-2026-27978
was published
for
next
(npm)
Mar 17, 2026
A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a...
Moderate
Unreviewed
CVE-2026-4271
was published
Mar 17, 2026
Apache Airflow: DAG authorization bypass
Moderate
CVE-2026-28563
was published
for
apache-airflow
(pip)
Mar 17, 2026
Missing Authorization vulnerability in Pluggabl Booster for WooCommerce allows Exploiting...
Moderate
Unreviewed
CVE-2026-32586
was published
Mar 17, 2026
A security flaw has been discovered in frdel/agent0ai agent-zero 0.9.7-10. The impacted element...
Moderate
Unreviewed
CVE-2026-4307
was published
Mar 17, 2026
A weakness has been identified in frdel/agent0ai agent-zero 0.9.7. This affects the function...
Moderate
Unreviewed
CVE-2026-4308
was published
Mar 17, 2026
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-2373
was published
Mar 17, 2026
A weakness has been identified in Tiandy Easy7 Integrated Management Platform 7.17.0. The...
Moderate
Unreviewed
CVE-2026-4288
was published
Mar 17, 2026
A vulnerability was determined in taoofagi easegen-admin up to...
Moderate
Unreviewed
CVE-2026-4284
was published
Mar 17, 2026
A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7...
Moderate
Unreviewed
CVE-2026-4289
was published
Mar 17, 2026
A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. The...
Moderate
Unreviewed
CVE-2026-4287
was published
Mar 17, 2026
A vulnerability was identified in taoofagi easegen-admin up to...
Moderate
Unreviewed
CVE-2026-4285
was published
Mar 17, 2026
A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.
Moderate
Unreviewed
CVE-2026-21991
was published
Mar 17, 2026
Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The...
Moderate
Unreviewed
CVE-2025-69693
was published
Mar 16, 2026
An Incorrect Access Control vulnerability exists in INDEX-EDUCATION PRONOTE prior to 2025.2.8....
Moderate
Unreviewed
CVE-2025-69727
was published
Mar 16, 2026
Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a...
Moderate
Unreviewed
CVE-2026-1629
was published
Mar 16, 2026
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2 fail to verify run_create permission for...
Moderate
Unreviewed
CVE-2026-26304
was published
Mar 16, 2026
Buffalo TeraStation NAS TS5400R firmware version 4.02-0.06 and prior contain an excessive file...
Moderate
Unreviewed
CVE-2026-29516
was published
Mar 16, 2026
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle...
Moderate
Unreviewed
CVE-2026-2454
was published
Mar 16, 2026
Admidio is Missing Authorization on Forum Topic and Post Deletion
Moderate
CVE-2026-32818
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Admidio has an HTMLPurifier Bypass in eCard Message Allows HTML Email Injection
Moderate
CVE-2026-32757
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Admidio Vulnerable to SSRF and Local File Read via Unrestricted URL Fetch in SSO Metadata Endpoint
Moderate
CVE-2026-32812
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Admidio is Missing CSRF Protection on Role Membership Date Changes
Moderate
CVE-2026-32755
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
ProTip!
Advisories are also available from the
GraphQL API