GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,599
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,828
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
470 advisories
Filter by severity
A Generation of Error Message Containing Sensitive Information vulnerability in the Materialized...
High
Unreviewed
CVE-2026-3259
was published
Apr 23, 2026
monetr: Server-side request forgery in Lunch Flow link creation and refresh
High
CVE-2026-41644
was published
for
github.com/monetr/monetr
(Go)
Apr 22, 2026
Meridian: Multiple defense-in-depth gaps (collection/depth caps, telemetry, retry, fan-out)
High
GHSA-f5v8-v6q3-q4h6
was published
for
Meridian.Mapping
(NuGet)
Apr 16, 2026
HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of...
Low
Unreviewed
CVE-2025-52641
was published
Apr 15, 2026
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication
High
CVE-2026-40245
was published
for
github.com/free5gc/udr
(Go)
Apr 14, 2026
Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor
High
CVE-2026-29146
was published
for
org.apache.tomcat:tomcat
(Maven)
Apr 9, 2026
A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated,...
Moderate
Unreviewed
CVE-2025-14243
was published
Apr 8, 2026
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.0,...
Moderate
Unreviewed
CVE-2026-24511
was published
Apr 8, 2026
Authorizer: CQL/N1QL Injection in Cassandra and Couchbase Backends via fmt.Sprintf String Interpolation
High
GHSA-jfwg-rxf3-p7r9
was published
for
github.com/authorizerdev/authorizer
(Go)
Apr 6, 2026
XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by...
High
Unreviewed
CVE-2025-71282
was published
Apr 1, 2026
Open WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`
Moderate
CVE-2026-28786
was published
for
open-webui
(pip)
Mar 27, 2026
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information...
Moderate
Unreviewed
CVE-2026-1262
was published
Mar 25, 2026
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information...
Moderate
Unreviewed
CVE-2026-2484
was published
Mar 25, 2026
HCL Traveler is affected by sensitive information disclosure. The application generates some...
Moderate
Unreviewed
CVE-2026-21783
was published
Mar 24, 2026
Keycloak's identity-first login flow exposes user information
Low
CVE-2026-4633
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques
High
CVE-2026-33192
was published
for
github.com/free5gc/udm
(Go)
Mar 18, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request
Moderate
CVE-2026-33065
was published
for
github.com/free5gc/udm
(Go)
Mar 18, 2026
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could...
Moderate
Unreviewed
CVE-2025-13726
was published
Mar 13, 2026
parse-server: Malformed `$regex` query leaks database error details in API response
Moderate
CVE-2026-30835
was published
for
parse-server
(npm)
Mar 6, 2026
Navtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote,...
Moderate
Unreviewed
CVE-2026-2752
was published
Mar 6, 2026
ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure...
Moderate
Unreviewed
CVE-2026-22052
was published
Mar 5, 2026
Curio exposes database credentials to users with network access through verbose HTTP error responses
High
GHSA-gj6x-q8rh-wj6x
was published
for
github.com/filecoin-project/curio
(Go)
Feb 26, 2026
Apache Airflow error reporting may expose full kwargs
Moderate
CVE-2025-65995
was published
for
apache-airflow
(pip)
Feb 21, 2026
OpenClaw session tool visibility hardening and Telegram webhook secret fallback
Moderate
CVE-2026-27004
was published
for
openclaw
(npm)
Feb 18, 2026
Libredesk has a SSRF Vulnerability in Webhooks
Moderate
CVE-2026-26957
was published
for
github.com/abhinavxd/libredesk
(Go)
Feb 18, 2026
ProTip!
Advisories are also available from the
GraphQL API