GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
773 advisories
Filter by severity
The affected Ebyte
product exports administrative credentials and other
sensitive...
High
Unreviewed
CVE-2026-77975
was published
Aug 31, 2026
browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in...
Moderate
Unreviewed
CVE-2026-82640
was published
Aug 30, 2026
openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client...
High
Unreviewed
CVE-2026-81683
was published
Aug 27, 2026
Prometheus Azure AD remote write OAuth client secret exposed via config API
High
CVE-2026-42151
was published
for
github.com/prometheus/prometheus
(Go)
May 5, 2026
A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for...
Moderate
Unreviewed
CVE-2026-66781
was published
Aug 18, 2026
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for...
Moderate
Unreviewed
CVE-2026-73834
was published
Aug 18, 2026
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a...
Moderate
Unreviewed
CVE-2025-59701
was published
Dec 2, 2025
Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob...
High
Unreviewed
CVE-2026-59657
was published
Aug 21, 2026
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
High
CVE-2026-61798
was published
for
io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl
(Maven)
Aug 20, 2026
In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with...
Moderate
Unreviewed
CVE-2026-76379
was published
Aug 20, 2026
In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with...
Moderate
Unreviewed
CVE-2026-76385
was published
Aug 20, 2026
In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who...
Moderate
Unreviewed
CVE-2026-76383
was published
Aug 20, 2026
In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who...
Moderate
Unreviewed
CVE-2026-76378
was published
Aug 20, 2026
In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with...
Moderate
Unreviewed
CVE-2026-76382
was published
Aug 20, 2026
In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with...
Moderate
Unreviewed
CVE-2026-76377
was published
Aug 20, 2026
In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who...
Moderate
Unreviewed
CVE-2026-76381
was published
Aug 20, 2026
In versions below 2.1.9 of the AWS IAM app for Splunk SOAR, a user who holds a role with...
Moderate
Unreviewed
CVE-2026-76376
was published
Aug 20, 2026
In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold...
Moderate
Unreviewed
CVE-2026-76405
was published
Aug 20, 2026
In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role...
Moderate
Unreviewed
CVE-2026-76380
was published
Aug 20, 2026
In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission...
Moderate
Unreviewed
CVE-2026-76386
was published
Aug 20, 2026
In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds...
Moderate
Unreviewed
CVE-2026-76384
was published
Aug 20, 2026
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows...
Moderate
Unreviewed
CVE-2026-21080
was published
Aug 10, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass...
Critical
Unreviewed
CVE-2026-15065
was published
Aug 19, 2026
A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long...
High
Unreviewed
CVE-2026-66782
was published
Aug 18, 2026
Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information...
Moderate
Unreviewed
CVE-2026-5224
was published
Aug 18, 2026
ProTip!
Advisories are also available from the
GraphQL API