GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
770 advisories
Filter by severity
Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob...
Unknown
Unreviewed
CVE-2026-59657
was published
Aug 21, 2026
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
High
CVE-2026-61798
was published
for
io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl
(Maven)
Aug 20, 2026
In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold...
Moderate
Unreviewed
CVE-2026-76405
was published
Aug 20, 2026
In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission...
Moderate
Unreviewed
CVE-2026-76386
was published
Aug 20, 2026
In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role...
Moderate
Unreviewed
CVE-2026-76380
was published
Aug 20, 2026
In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with...
Moderate
Unreviewed
CVE-2026-76377
was published
Aug 20, 2026
In versions below 2.1.9 of the AWS IAM app for Splunk SOAR, a user who holds a role with...
Moderate
Unreviewed
CVE-2026-76376
was published
Aug 20, 2026
In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with...
Moderate
Unreviewed
CVE-2026-76379
was published
Aug 20, 2026
In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with...
Moderate
Unreviewed
CVE-2026-76385
was published
Aug 20, 2026
In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds...
Moderate
Unreviewed
CVE-2026-76384
was published
Aug 20, 2026
In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who...
Moderate
Unreviewed
CVE-2026-76383
was published
Aug 20, 2026
In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with...
Moderate
Unreviewed
CVE-2026-76382
was published
Aug 20, 2026
In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who...
Moderate
Unreviewed
CVE-2026-76378
was published
Aug 20, 2026
In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who...
Moderate
Unreviewed
CVE-2026-76381
was published
Aug 20, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass...
Critical
Unreviewed
CVE-2026-15065
was published
Aug 19, 2026
A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for...
Moderate
Unreviewed
CVE-2026-66781
was published
Aug 18, 2026
A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long...
High
Unreviewed
CVE-2026-66782
was published
Aug 18, 2026
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for...
Moderate
Unreviewed
CVE-2026-73834
was published
Aug 18, 2026
Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information...
Moderate
Unreviewed
CVE-2026-5224
was published
Aug 18, 2026
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so...
Moderate
Unreviewed
CVE-2026-68970
was published
Aug 12, 2026
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in...
Moderate
Unreviewed
CVE-2026-66016
was published
Aug 12, 2026
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in...
Moderate
Unreviewed
CVE-2026-59244
was published
Aug 12, 2026
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to...
Moderate
Unreviewed
CVE-2026-61928
was published
Aug 11, 2026
A flaw was found in insights-core where the password redaction layer fails to recognize...
Moderate
Unreviewed
CVE-2026-19391
was published
Aug 11, 2026
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows...
Moderate
Unreviewed
CVE-2026-21080
was published
Aug 10, 2026
ProTip!
Advisories are also available from the
GraphQL API