GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,460
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,142
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
43,896 advisories
Filter by severity
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows...
High
Unreviewed
CVE-2026-66421
was published
Jul 31, 2026
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows...
Critical
Unreviewed
CVE-2026-66418
was published
Jul 30, 2026
IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and...
Moderate
Unreviewed
CVE-2025-0152
was published
Jul 30, 2026
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is...
Critical
Unreviewed
CVE-2026-11707
was published
Jul 30, 2026
IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0...
Moderate
Unreviewed
CVE-2025-36431
was published
Jul 30, 2026
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is...
Moderate
Unreviewed
CVE-2026-11383
was published
Jul 30, 2026
IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through...
Moderate
Unreviewed
CVE-2025-36298
was published
Jul 30, 2026
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site...
High
Unreviewed
CVE-2026-16969
was published
Jul 30, 2026
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site...
High
Unreviewed
CVE-2026-18361
was published
Jul 30, 2026
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site...
High
Unreviewed
CVE-2026-18360
was published
Jul 30, 2026
Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native...
Moderate
Unreviewed
CVE-2026-59328
was published
Jul 30, 2026
The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting...
Moderate
Unreviewed
CVE-2026-14318
was published
Jul 30, 2026
The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any...
Moderate
Unreviewed
CVE-2026-14592
was published
Jul 30, 2026
The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a...
Moderate
Unreviewed
CVE-2026-14207
was published
Jul 30, 2026
The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG...
Moderate
Unreviewed
CVE-2026-13330
was published
Jul 30, 2026
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag...
Moderate
Unreviewed
CVE-2026-13344
was published
Jul 30, 2026
The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form...
Moderate
Unreviewed
CVE-2026-11881
was published
Jul 30, 2026
Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote...
Moderate
Unreviewed
CVE-2026-17962
was published
Jul 30, 2026
Insufficient policy enforcement in Chromecast in Google Chrome prior to 151.0.7922.72 allowed an...
Moderate
Unreviewed
CVE-2026-17903
was published
Jul 30, 2026
Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote...
Moderate
Unreviewed
CVE-2026-17878
was published
Jul 30, 2026
Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote...
Moderate
Unreviewed
CVE-2026-17734
was published
Jul 30, 2026
Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an...
Moderate
Unreviewed
CVE-2026-17739
was published
Jul 30, 2026
Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a...
Moderate
Unreviewed
CVE-2026-17728
was published
Jul 30, 2026
Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in...
Moderate
Unreviewed
CVE-2025-65337
was published
Jul 29, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19...
Moderate
Unreviewed
CVE-2026-3093
was published
Jul 29, 2026
ProTip!
Advisories are also available from the
GraphQL API