GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
150,381 advisories
Filter by severity
A flaw was found in libsoup. An unsigned integer underflow in the...
Moderate
Unreviewed
CVE-2026-66337
was published
Jul 25, 2026
A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing...
Moderate
Unreviewed
CVE-2026-66338
was published
Jul 25, 2026
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup...
Moderate
Unreviewed
CVE-2026-66339
was published
Jul 25, 2026
The web management interface in
Tycon Systems TPDIN-Monitor-WEB2
stores and displays system...
Moderate
Unreviewed
CVE-2026-55985
was published
Jul 25, 2026
Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown...
Moderate
Unreviewed
CVE-2026-57530
was published
Jul 24, 2026
Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin...
Moderate
Unreviewed
CVE-2026-57531
was published
Jul 24, 2026
BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the...
Moderate
Unreviewed
CVE-2026-66004
was published
Jul 24, 2026
Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its...
Moderate
Unreviewed
CVE-2026-66005
was published
Jul 24, 2026
Improper neutralization of input during web page generation ('cross-site scripting')...
Moderate
Unreviewed
CVE-2026-8308
was published
Jul 24, 2026
lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability...
Moderate
Unreviewed
CVE-2026-66006
was published
Jul 24, 2026
Datasets through 5.0.0, fixed in f989ef9, contains a path traversal vulnerability in folder-based...
Moderate
Unreviewed
CVE-2026-66007
was published
Jul 24, 2026
Insertion of sensitive information into sent data in the automation jobs API in Devolutions...
Moderate
Unreviewed
CVE-2026-16798
was published
Jul 24, 2026
Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L...
Moderate
Unreviewed
CVE-2026-55731
was published
Jul 24, 2026
A flaw was found in the role-users endpoint of the keycloak-services library, which is the core...
Moderate
Unreviewed
CVE-2026-17059
was published
Jul 24, 2026
Improper access control in the automation tests and workflows features in Devolutions PowerShell...
Moderate
Unreviewed
CVE-2026-16799
was published
Jul 24, 2026
Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell...
Moderate
Unreviewed
CVE-2026-16802
was published
Jul 24, 2026
Missing Authorization vulnerability in Apache HBase thrift and rest delegation service.
A scan...
Moderate
Unreviewed
CVE-2026-49326
was published
Jul 24, 2026
Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer...
Moderate
Unreviewed
CVE-2026-66008
was published
Jul 24, 2026
External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co....
Moderate
Unreviewed
CVE-2026-7484
was published
Jul 24, 2026
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed...
Moderate
Unreviewed
CVE-2026-66010
was published
Jul 24, 2026
A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and...
Moderate
Unreviewed
CVE-2026-17048
was published
Jul 24, 2026
Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL...
Moderate
Unreviewed
CVE-2026-66009
was published
Jul 24, 2026
Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy...
Moderate
Unreviewed
CVE-2026-45812
was published
Jul 24, 2026
Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could...
Moderate
Unreviewed
CVE-2026-46452
was published
Jul 24, 2026
A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user...
Moderate
Unreviewed
CVE-2026-16743
was published
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API