GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,458
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,141
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
45 advisories
Filter by severity
In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and...
Moderate
Unreviewed
CVE-2026-50252
was published
Jul 22, 2026
Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous...
Critical
Unreviewed
CVE-2026-41120
was published
Jun 25, 2026
A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads...
High
Unreviewed
CVE-2026-33612
was published
Jun 25, 2026
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering...
Critical
Unreviewed
CVE-2026-45602
was published
Jun 9, 2026
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous...
Moderate
Unreviewed
CVE-2026-42960
was published
May 20, 2026
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
Low
CVE-2026-46342
was published
for
@nuxt/nitro-server
(npm)
May 19, 2026
Next.js's Middleware / Proxy redirects can be cache-poisoned
Low
CVE-2026-44572
was published
for
next
(npm)
May 11, 2026
gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
High
CVE-2026-40034
was published
for
gix
(Rust)
May 5, 2026
Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized...
High
Unreviewed
CVE-2026-32162
was published
Apr 14, 2026
OpenClaw: Zalo replay dedupe keys could suppress messages across chats or senders
Moderate
CVE-2026-41354
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw has an Arbitrary Malicious Code Execution Vulnerability
High
CVE-2026-35641
was published
for
openclaw
(npm)
Mar 30, 2026
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport...
High
Unreviewed
CVE-2026-1642
was published
Feb 4, 2026
In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote...
Moderate
Unreviewed
CVE-2025-68269
was published
Dec 16, 2025
An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in...
Low
Unreviewed
CVE-2025-1680
was published
Oct 23, 2025
Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an...
High
Unreviewed
CVE-2025-40778
was published
Oct 22, 2025
NLnet Labs Unbound up to and including version 1.24.0 is vulnerable to possible domain hijack...
Moderate
Unreviewed
CVE-2025-11411
was published
Oct 22, 2025
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in...
Moderate
Unreviewed
CVE-2025-11703
was published
Oct 18, 2025
A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in...
High
Unreviewed
CVE-2025-5994
was published
Jul 16, 2025
A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be...
High
Unreviewed
CVE-2025-40776
was published
Jul 16, 2025
Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an...
Moderate
Unreviewed
CVE-2025-48804
was published
Jul 8, 2025
A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated,...
Moderate
Unreviewed
CVE-2025-20255
was published
May 21, 2025
Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized...
High
Unreviewed
CVE-2025-29842
was published
May 13, 2025
Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a...
High
Unreviewed
CVE-2025-29816
was published
Apr 8, 2025
Nuxt allows DOS via cache poisoning with payload rendering response
High
CVE-2025-27415
was published
for
nuxt
(npm)
Mar 19, 2025
check-jsonschema default caching for remote schemas allows for cache confusion
Moderate
CVE-2024-53848
was published
for
check-jsonschema
(pip)
Dec 2, 2024
ProTip!
Advisories are also available from the
GraphQL API