GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
353,227 advisories
Filter by severity
GitHub CLI has an incorrect authorization header in API requests to TUF repository mirrors via `gh attestation`, `gh release verify`, and `gh release verify-asset` commands
High
CVE-2026-48501
was published
for
github.com/cli/cli/v2
(Go)
May 29, 2026
A vulnerability, which was classified as problematic, was found in Linux Kernel. This affects the...
High
Unreviewed
CVE-2022-3566
was published
Oct 18, 2022
A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc...
High
Unreviewed
CVE-2026-52722
was published
Jun 15, 2026
The credentials for the local user "user-app" may be exposed in log files, potentially enabling a...
Moderate
Unreviewed
CVE-2026-44105
was published
Jul 30, 2026
A privilege escalation vulnerability in the init-script for user-applications allows a low...
High
Unreviewed
CVE-2026-44106
was published
Jul 30, 2026
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition...
High
Unreviewed
CVE-2026-44094
was published
Jul 30, 2026
An unauthenticated remote attacker can inject malicious firmware into the internal charging...
Moderate
Unreviewed
CVE-2026-44103
was published
Jul 30, 2026
An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the...
High
Unreviewed
CVE-2026-44091
was published
Jul 30, 2026
A reboot of the charging controller can be triggered via Modbus TCP without authentication....
High
Unreviewed
CVE-2026-44107
was published
Jul 30, 2026
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated...
Critical
Unreviewed
CVE-2026-44108
was published
Jul 30, 2026
An unauthenticated remote attacker can inject malicious input into the ModbusServer application...
High
Unreviewed
CVE-2026-44092
was published
Jul 30, 2026
Improper Enforcement of Message Integrity During Transmission in a Communication Channel...
High
Unreviewed
CVE-2026-13584
was published
Jul 30, 2026
A privilege escalation vulnerability in a script used for network configuration allows a low...
High
Unreviewed
CVE-2026-44095
was published
Jul 30, 2026
A local privilege escalation vulnerability in the init-script for user-applications allows a low...
High
Unreviewed
CVE-2026-44093
was published
Jul 30, 2026
Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker,...
Critical
Unreviewed
CVE-2026-44090
was published
Jul 30, 2026
An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by...
Moderate
Unreviewed
CVE-2026-44102
was published
Jul 30, 2026
Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote...
Critical
Unreviewed
CVE-2026-44101
was published
Jul 30, 2026
Due to improper neutralization of special elements, an unauthenticated remote attacker is able to...
Critical
Unreviewed
CVE-2026-7849
was published
Jul 30, 2026
The firmware update process for the basemodule of the charging controller only validates the...
Critical
Unreviewed
CVE-2026-44104
was published
Jul 30, 2026
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend...
High
Unreviewed
CVE-2026-44098
was published
Jul 30, 2026
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute...
High
Unreviewed
CVE-2026-44096
was published
Jul 30, 2026
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST...
Moderate
Unreviewed
CVE-2026-44097
was published
Jul 30, 2026
A privilege escalation vulnerability in the system configuration allows a low-privileged local...
High
Unreviewed
CVE-2026-44099
was published
Jul 30, 2026
The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging...
High
Unreviewed
CVE-2026-44100
was published
Jul 30, 2026
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in...
Moderate
Unreviewed
CVE-2026-55653
was published
Jun 23, 2026
ProTip!
Advisories are also available from the
GraphQL API