GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
55
GitHub Actions
50
Go
3,722
Maven
5,000+
npm
5,000+
NuGet
935
pip
4,946
Pub
13
RubyGems
1,055
Rust
1,338
Swift
54
Unreviewed advisories
All unreviewed
5,000+
17 advisories
Filter by severity
A vulnerability has been identified in SCALANCE XB205-3 (SC, PN) (All versions < V4.5), SCALANCE...
High
Unreviewed
CVE-2023-44317
was published
Nov 14, 2023
Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4...
High
Unreviewed
CVE-2024-41924
was published
Jul 30, 2024
Artifact poisoning vulnerability in action-download-artifact v5 and earlier
High
GHSA-5xr6-xhww-33m4
was published
for
dawidd6/action-download-artifact
(GitHub Actions)
Nov 25, 2024
Nuxt allows DOS via cache poisoning with payload rendering response
High
CVE-2025-27415
was published
for
nuxt
(npm)
Mar 19, 2025
Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a...
High
Unreviewed
CVE-2025-29816
was published
Apr 8, 2025
Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized...
High
Unreviewed
CVE-2025-29842
was published
May 13, 2025
A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be...
High
Unreviewed
CVE-2025-40776
was published
Jul 16, 2025
A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in...
High
Unreviewed
CVE-2025-5994
was published
Jul 16, 2025
Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an...
High
Unreviewed
CVE-2025-40778
was published
Oct 22, 2025
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport...
High
Unreviewed
CVE-2026-1642
was published
Feb 4, 2026
OpenClaw has an Arbitrary Malicious Code Execution Vulnerability
High
CVE-2026-35641
was published
for
openclaw
(npm)
Mar 30, 2026
Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized...
High
Unreviewed
CVE-2026-32162
was published
Apr 14, 2026
gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
High
GHSA-f26g-jm89-4g65
was published
for
gix
(Rust)
May 5, 2026
ProTip!
Advisories are also available from the
GraphQL API