GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
12,451 advisories
Filter by severity
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform...
Moderate
Unreviewed
CVE-2026-20254
was published
Jun 10, 2026
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform...
Moderate
Unreviewed
CVE-2026-20257
was published
Jun 10, 2026
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform...
Moderate
Unreviewed
CVE-2026-20255
was published
Jun 10, 2026
Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header...
Moderate
Unreviewed
CVE-2026-41727
was published
Jun 10, 2026
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an...
Moderate
Unreviewed
CVE-2026-47903
was published
Jun 10, 2026
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an...
High
Unreviewed
CVE-2026-34712
was published
Jun 10, 2026
SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch
Moderate
CVE-2026-47767
was published
for
symfony/runtime
(Composer)
Jun 9, 2026
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation...
High
Unreviewed
CVE-2026-47930
was published
Jun 9, 2026
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation...
High
Unreviewed
CVE-2026-47931
was published
Jun 9, 2026
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation...
Critical
Unreviewed
CVE-2026-47928
was published
Jun 9, 2026
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Input Validation...
Moderate
Unreviewed
CVE-2026-47909
was published
Jun 9, 2026
Insufficient authentication and input validation in the listed NETGEAR models allow users...
Moderate
Unreviewed
CVE-2026-9212
was published
Jun 9, 2026
A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to...
Moderate
Unreviewed
CVE-2026-9213
was published
Jun 9, 2026
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated...
Moderate
Unreviewed
CVE-2026-9210
was published
Jun 9, 2026
An unauthenticated user on the local network can gain control of the router and make unauthorized...
Moderate
Unreviewed
CVE-2026-9211
was published
Jun 9, 2026
Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a...
High
Unreviewed
CVE-2026-48569
was published
Jun 9, 2026
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an...
Low
Unreviewed
CVE-2026-48288
was published
Jun 9, 2026
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an...
Low
Unreviewed
CVE-2026-48289
was published
Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft...
Moderate
Unreviewed
CVE-2026-47641
was published
Jun 9, 2026
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation...
Low
Unreviewed
CVE-2026-45642
was published
Jun 9, 2026
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
High
Unreviewed
CVE-2026-45636
was published
Jun 9, 2026
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges...
High
Unreviewed
CVE-2026-44811
was published
Jun 9, 2026
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate...
High
Unreviewed
CVE-2026-40376
was published
Jun 9, 2026
Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual...
Moderate
Unreviewed
CVE-2026-0412
was published
Jun 9, 2026
Authenticated administrators connected to the local network can gain
elevated access to the...
Low
Unreviewed
CVE-2026-0410
was published
Jun 9, 2026
ProTip!
Advisories are also available from the
GraphQL API