GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
379 advisories
Filter by severity
In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication...
Moderate
Unreviewed
CVE-2026-86497
was published
Sep 7, 2026
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to...
Low
Unreviewed
CVE-2026-86505
was published
Sep 7, 2026
Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready...
Moderate
Unreviewed
CVE-2026-85307
was published
Sep 3, 2026
Hurl: Cookies in Cookies section leak when redirecting to a different host
Moderate
CVE-2026-63481
was published
for
hurl
(Rust)
Sep 2, 2026
Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability...
Moderate
Unreviewed
CVE-2026-77123
was published
Sep 2, 2026
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best...
Moderate
Unreviewed
CVE-2026-81162
was published
Sep 2, 2026
pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
High
GHSA-vx52-2968-3vc6
was published
for
pnpm
(npm)
Sep 1, 2026
Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <...
Moderate
Unreviewed
CVE-2026-81280
was published
Aug 31, 2026
urllib's cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage
High
CVE-2026-55553
was published
for
urllib
(npm)
Aug 25, 2026
Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.
High
Unreviewed
CVE-2026-66585
was published
Aug 24, 2026
SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the...
Moderate
Unreviewed
CVE-2026-59809
was published
Aug 22, 2026
Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient...
High
Unreviewed
CVE-2026-75953
was published
Aug 19, 2026
Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
High
Unreviewed
CVE-2026-73384
was published
Aug 19, 2026
Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0...
High
Unreviewed
CVE-2026-73386
was published
Aug 19, 2026
Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17...
Moderate
Unreviewed
CVE-2026-74008
was published
Aug 18, 2026
Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.
High
Unreviewed
CVE-2026-66443
was published
Aug 13, 2026
Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.
High
Unreviewed
CVE-2026-66463
was published
Aug 13, 2026
Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
Moderate
Unreviewed
CVE-2026-28174
was published
Aug 13, 2026
OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass...
Moderate
Unreviewed
CVE-2026-16637
was published
Aug 7, 2026
Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
Moderate
Unreviewed
CVE-2026-66696
was published
Aug 6, 2026
Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.
Moderate
Unreviewed
CVE-2026-66683
was published
Aug 6, 2026
Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.
Moderate
Unreviewed
CVE-2026-66684
was published
Aug 6, 2026
Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
Moderate
Unreviewed
CVE-2026-66685
was published
Aug 6, 2026
Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
High
Unreviewed
CVE-2026-65543
was published
Aug 6, 2026
Google::Auth versions before 0.09 for Perl allow server side request forgery and credential...
High
Unreviewed
CVE-2026-66901
was published
Aug 4, 2026
ProTip!
Advisories are also available from the
GraphQL API