GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
47
Go
3,295
Maven
5,000+
npm
5,000+
NuGet
876
pip
4,524
Pub
12
RubyGems
1,008
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
153,193 advisories
Filter by severity
SHARP routers do not perform authentication for some web APIs. The device information may be...
Moderate
Unreviewed
CVE-2026-32326
was published
Mar 25, 2026
The Easy Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2026-4766
was published
Mar 25, 2026
A vulnerability was found in code-projects Simple Laundry System 1.0. This affects an unknown...
Moderate
Unreviewed
CVE-2026-4784
was published
Mar 25, 2026
A vulnerability has been found in itsourcecode College Management System 1.0. The impacted...
Moderate
Unreviewed
CVE-2026-4783
was published
Mar 25, 2026
Open Redirect vulnerability in Hitachi Ops Center Administrator.This issue affects Hitachi Ops...
Moderate
Unreviewed
CVE-2026-1166
was published
Mar 25, 2026
A security flaw has been discovered in SourceCodester Sales and Inventory System 1.0. This...
Moderate
Unreviewed
CVE-2026-4777
was published
Mar 25, 2026
A flaw has been found in SourceCodester Sales and Inventory System 1.0. The affected element is...
Moderate
Unreviewed
CVE-2026-4781
was published
Mar 25, 2026
A vulnerability was detected in SourceCodester Sales and Inventory System 1.0. Impacted is an...
Moderate
Unreviewed
CVE-2026-4780
was published
Mar 25, 2026
A security vulnerability has been detected in SourceCodester Sales and Inventory System 1.0. This...
Moderate
Unreviewed
CVE-2026-4779
was published
Mar 25, 2026
A weakness has been identified in SourceCodester Sales and Inventory System 1.0. This...
Moderate
Unreviewed
CVE-2026-4778
was published
Mar 25, 2026
Ech0 authenticated user-list exposed data via public `/api/allusers` endpoint
Moderate
CVE-2026-33638
was published
for
github.com/lin-snow/ech0
(Go)
Mar 24, 2026
Scriban has Multiple Denial-of-Service Vectors via Unbounded Resource Consumption During Expression Evaluation
Moderate
GHSA-xw6w-9jjh-p9cr
was published
for
Scriban
(NuGet)
Mar 24, 2026
Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString
Moderate
GHSA-m2p3-hwv5-xpqw
was published
for
Scriban
(NuGet)
Mar 24, 2026
NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
Moderate
CVE-2026-33248
was published
for
github.com/nats-io/nats-server/v2
(Go)
Mar 24, 2026
NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
Moderate
CVE-2026-33246
was published
for
github.com/nats-io/nats-server/v2
(Go)
Mar 24, 2026
NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing
Moderate
CVE-2026-33223
was published
for
github.com/nats-io/nats-server/v2
(Go)
Mar 24, 2026
NATS JetStream has an authorization bypass through its Management API
Moderate
CVE-2026-33222
was published
for
github.com/nats-io/nats-server/v2
(Go)
Mar 24, 2026
NATS is vulnerable to pre-auth DoS through WebSockets client service
Moderate
CVE-2026-33219
was published
for
github.com/nats-io/nats-server/v2
(Go)
Mar 24, 2026
NATS is vulnerable to MQTT hijacking via Client ID
Moderate
CVE-2026-33215
was published
for
github.com/nats-io/nats-server/v2
(Go)
Mar 24, 2026
An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket,...
Moderate
Unreviewed
CVE-2026-4433
was published
Mar 24, 2026
NVIDIA B300 MCU contains a vulnerability in the CX8 MCU that could allow a malicious actor to...
Moderate
Unreviewed
CVE-2025-33242
was published
Mar 24, 2026
NVIDIA SNAP-4 Container contains a vulnerability in the VIRTIO-BLK component where a malicious...
Moderate
Unreviewed
CVE-2025-33215
was published
Mar 24, 2026
HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could...
Moderate
Unreviewed
CVE-2026-21790
was published
Mar 24, 2026
NVIDIA SNAP-4 Container contains a vulnerability in the configuration interface where an attacker...
Moderate
Unreviewed
CVE-2025-33216
was published
Mar 24, 2026
HCL Traveler is affected by sensitive information disclosure. The application generates some...
Moderate
Unreviewed
CVE-2026-21783
was published
Mar 24, 2026
ProTip!
Advisories are also available from the
GraphQL API