GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
523 advisories
Filter by severity
An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the storage of...
High
Unreviewed
CVE-2026-78860
was published
Oct 5, 2026
Applications built on MongoDB Entity Framework Core Provider which place a database name in the...
Moderate
Unreviewed
CVE-2026-92757
was published
Sep 17, 2026
Applications built on MongoDB Entity Framework Core Provider which combine independent encryption...
Moderate
Unreviewed
CVE-2026-92756
was published
Sep 17, 2026
Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job...
Moderate
Unreviewed
CVE-2026-84676
was published
Sep 2, 2026
openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the...
High
Unreviewed
CVE-2026-81688
was published
Aug 27, 2026
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB...
Critical
Unreviewed
CVE-2026-81681
was published
Aug 27, 2026
DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth...
Critical
Unreviewed
CVE-2026-77812
was published
Aug 21, 2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents,...
High
Unreviewed
CVE-2025-59325
was published
Aug 12, 2026
Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent...
High
Unreviewed
CVE-2026-21079
was published
Aug 10, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
Low
GHSA-464c-974j-9xm6
was published
for
@aws-cdk/aws-codebuild
(Go)
Jul 24, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS...
High
Unreviewed
CVE-2026-20157
was published
Jul 15, 2026
CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
High
CVE-2026-54784
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
Moderate
CVE-2026-55568
was published
for
guzzlehttp/guzzle
(Composer)
Jun 19, 2026
Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations
Moderate
CVE-2026-53442
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
Apache Tomcat Missing Encryption of Sensitive Data vulnerability
High
CVE-2026-34486
was published
for
org.apache.tomcat:tomcat
(Maven)
Apr 9, 2026
Antrea has Missing Encryption of Sensitive Data
High
CVE-2026-34992
was published
for
antrea.io/antrea
(Go)
Apr 3, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure
Critical
CVE-2026-27944
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 5, 2026
Rancher's weave CNI password is not configured when a cluster is created from an RKE template
Moderate
CVE-2022-21951
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due...
Moderate
Unreviewed
CVE-2025-15548
was published
Jan 29, 2026
A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with...
High
Unreviewed
CVE-2025-13453
was published
Jan 15, 2026
Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X....
Critical
Unreviewed
CVE-2025-36751
was published
Dec 13, 2025
When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS...
High
Unreviewed
CVE-2025-13053
was published
Dec 12, 2025
The firmware on the basestation of the Meatmeet is not encrypted. An adversary with physical...
Moderate
Unreviewed
CVE-2025-65825
was published
Dec 10, 2025
Jenkins Curseforge Publisher Plugin does not mask API Keys displayed on the job configuration form
Moderate
CVE-2025-64147
was published
for
org.jenkins-ci.plugins:curseforge-publisher
(Maven)
Oct 29, 2025
Jenkins ByteGuard Build Actions Plugin stores API tokens unencrypted in job config.xml files
Moderate
CVE-2025-64144
was published
for
io.jenkins.plugins:byteguard-build-actions
(Maven)
Oct 29, 2025
ProTip!
Advisories are also available from the
GraphQL API