GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,494
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
56 advisories
Filter by severity
A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function...
Low
Unreviewed
CVE-2026-15186
was published
Jul 9, 2026
A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown...
Low
Unreviewed
CVE-2026-13493
was published
Jun 28, 2026
A security flaw has been discovered in medkey-org medkey up to...
Low
Unreviewed
CVE-2026-12207
was published
Jun 15, 2026
A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this...
Low
Unreviewed
CVE-2026-10624
was published
Jun 2, 2026
A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue...
Low
Unreviewed
CVE-2026-10299
was published
Jun 2, 2026
A security vulnerability has been detected in OUSL-GROUP-BrinaryBrains School Student Management...
Low
Unreviewed
CVE-2026-10168
was published
May 31, 2026
A vulnerability was found in yashpokharna2555 StudentManagementSystem...
Low
Unreviewed
CVE-2026-9438
was published
May 26, 2026
Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS...
Moderate
Unreviewed
CVE-2026-33603
was published
May 12, 2026
xxl-job has a Resource Injection issue
Low
CVE-2026-7303
was published
for
com.xuxueli:xxl-job-admin
(Maven)
Apr 29, 2026
A security flaw has been discovered in Newgen OmniDocs up to 12.0.00. Affected by this issue is...
Moderate
Unreviewed
CVE-2026-5414
was published
Apr 2, 2026
A vulnerability was found in BichitroGan ISP Billing Software 2025.3.20. Impacted is an unknown...
Moderate
Unreviewed
CVE-2026-5031
was published
Mar 29, 2026
A flaw has been found in Shy2593666979 AgentChat up to 2.3.0. This issue affects the function...
Moderate
Unreviewed
CVE-2026-3693
was published
Mar 8, 2026
EverShop is vulnerable to Unauthorized Order Information Access (IDOR)
Low
CVE-2025-12919
was published
for
@evershop/evershop
(npm)
Nov 9, 2025
Skuul School Management System has an Insecure Direct Object Reference (IDOR) Vulnerability in View Fee Invoice
Low
CVE-2025-12918
was published
for
yungifez/skuul
(Composer)
Nov 9, 2025
A vulnerability was determined in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The...
Moderate
Unreviewed
CVE-2025-12270
was published
Oct 27, 2025
A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow...
High
Unreviewed
CVE-2025-43491
was published
Sep 9, 2025
A security flaw has been discovered in E4 Sistemas Mercatus ERP 2.00.019. The affected element is...
Moderate
Unreviewed
CVE-2025-9619
was published
Aug 29, 2025
xxl-job Jobs Handler remove function allows improper control of resource identifiers via ID parameter
Low
CVE-2025-9264
was published
for
com.xuxueli:xxl-job-admin
(Maven)
Aug 21, 2025
xxl-job Vulnerable to Resource Injection and Authorization Bypass Through User-Controlled Key
Low
CVE-2025-9263
was published
for
com.xuxueli:xxl-job-admin
(Maven)
Aug 21, 2025
A vulnerability classified as problematic was found in LitmusChaos Litmus up to 3.19.0. Affected...
Moderate
Unreviewed
CVE-2025-8793
was published
Aug 10, 2025
A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus...
Low
Unreviewed
CVE-2025-6534
was published
Jun 26, 2025
Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP...
High
Unreviewed
CVE-2025-2410
was published
May 22, 2025
A vulnerability was found in CodeCanyon RISE Ultimate Project Manager 3.8.2 and classified as...
Moderate
Unreviewed
CVE-2025-3855
was published
Apr 22, 2025
Overview
The product receives input from an upstream component, but it does not restrict...
Critical
Unreviewed
CVE-2025-0756
was published
Apr 17, 2025
A vulnerability was found in FCJ Venture Builder appclientefiel 3.0.27. It has been declared as...
Moderate
Unreviewed
CVE-2025-3405
was published
Apr 8, 2025
ProTip!
Advisories are also available from the
GraphQL API