GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
10 advisories
Filter by severity
Fleet vulnerable to SQL Injection in MDM bootstrap package by authenticated team or global admin
Moderate
CVE-2026-34386
was published
for
github.com/fleetdm/fleet/v4
(Go)
Mar 30, 2026
Fleet's Apple MDM profile delivery has second-order SQL Injection that can compromise the database
Moderate
CVE-2026-34385
was published
for
github.com/fleetdm/fleet/v4
(Go)
Mar 30, 2026
A Fleet team maintainer can transfer hosts from any team via missing source team authorization
Moderate
CVE-2026-29180
was published
for
github.com/fleetdm/fleet/v4
(Go)
Mar 27, 2026
Fleet: Sensitive Google Calendar credentials disclosed to low-privileged users
High
CVE-2026-27465
was published
for
github.com/fleetdm/fleet/v4
(Go)
Feb 26, 2026
Fleet: Authorization Bypass in certificate template batch deletion for team administrators
Moderate
CVE-2026-25963
was published
for
github.com/fleetdm/fleet/v4
(Go)
Feb 26, 2026
Fleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpoint
Moderate
CVE-2026-24004
was published
for
github.com/fleetdm/fleet/v4
(Go)
Feb 26, 2026
Fleet: Device lock PIN can be predicted if lock time is known
Moderate
CVE-2026-23999
was published
for
github.com/fleetdm/fleet/v4
(Go)
Feb 26, 2026
Fleet has a JWT signature bypass vulnerability in Azure AD MDM enrollment
Critical
CVE-2026-23518
was published
for
github.com/fleetdm/fleet
(Go)
Jan 20, 2026
Fleet has an Access Control vulnerability in debug/pprof endpoints
High
CVE-2026-23517
was published
for
github.com/fleetdm/fleet
(Go)
Jan 20, 2026
Fleet Windows MDM endpoint has a Cross-site Scripting vulnerability
Moderate
CVE-2026-22808
was published
for
github.com/fleetdm/fleet
(Go)
Jan 20, 2026
ProTip!
Advisories are also available from the
GraphQL API