Vendor Security Advisories

Security advisories straight from the source — GitHub, Red Hat, Microsoft, Cisco and beyond. Searchable, indexed, and polled hourly, with the time we first saw each one recorded on the advisory.

Live56,952 advisories tracked677 disclosed before NVD5,280 Critical26,726 High18,491 Medium2,759 Low
10 vendors tracked· 480 ingested in last 24h← Back to CVE Pulse

🔔 Vendor advisory alerts

Catch vendor-disclosed advisories the day they ship

Vendors like Microsoft, Red Hat, and GitHub publish security advisories days to weeks before NVD assigns a CVE. Subscribe to get these the moment we ingest them.

  • Microsoft MSRC, Red Hat RHSA, GitHub GHSA — full vendor coverage
  • Embargo-window disclosures included (Pre-CVE advisories)
  • Real-time, daily, weekly, or monthly cadence

Free · Unsubscribe in one click · No marketing email

Browse by vendor

10 active · 10 tracked
Disclosed before NVD assigned a CVE-ID677 total

These advisories were published by the upstream vendor before NVD assigned a CVE-ID. Customers received the email on day zero — everyone else has to wait days to weeks for NVD to catch up.

GHSA-jm5p-837g-rv8gGitHub6.5

Wagtail: Improper restriction handling on Page translation API endpoint

MEDIUMAug 20, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-x5cx-w6p2-mxf2GitHub6.5

Wagtail: Improper permission handling when copying snippets

MEDIUMAug 20, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-c2xx-cjmh-9q8fGitHub5.3

Wagtail: Improper restriction handling on descendant collections in Documents and Images API

MEDIUMAug 20, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-92hv-j533-69wcGitHub3.7

Wagtail: Identification of documents by SHA1 hash

LOWAug 20, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-hq84-x37p-j6q5GitHub4.5

Winter: Reflected XSS through the search query parameter in the backend Table widget

MEDIUMAug 20, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-p2ch-c2c3-4xm5GitHub6.1

Winter: CSRF through AJAX handler names reachable as backend page actions

MEDIUMAug 20, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-5cwr-5jxg-pcf6GitHub4.5

Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles

MEDIUMAug 20, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-fm29-4mq3-phg6GitHub5.3

Winter: ImportExportController AJAX handlers bypass granular import/export permission gate

MEDIUMAug 20, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-mpmw-f6h6-3g26GitHub4.3

Winter: My Account preview exposes another backend user's profile by record ID

MEDIUMAug 20, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-7mpf-4465-7fc2GitHub2.0

Winter: Stored XSS through Backend List widget image columns

LOWAug 20, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-rxhg-vcww-2mpwGitHub3.1

Fleet: ORDER BY column injection on activity list endpoints

LOWAug 20, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-q9c5-pp7m-fm2gGitHub5.3

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs

MEDIUMAug 20, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
Most Recent Vendor Advisoriestop 12

The newest 12 advisories ingested from any tracked vendor — refreshed every two minutes.

GHSA-78xj-r982-5m2qGitHub

Improper input validation and Exposure of sensitive information through data queries...

HIGHAug 21, 2026View details →
GHSA-5hvp-9mcx-5245GitHub

A critical bypass access control vulnerability has been reported in PTC Windchill Risk and...

CRITICALAug 21, 2026View details →
GHSA-wj6g-rh9q-6vvmGitHub9.8

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as...

CRITICALAug 21, 2026View details →
GHSA-2698-qwmx-3r6fGitHub

A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and...

HIGHAug 21, 2026View details →
GHSA-m4rr-rf2f-g267GitHub

Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux...

MEDIUMAug 21, 2026View details →
GHSA-qxmv-9q88-wwmwGitHub

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC...

CRITICALAug 21, 2026View details →
GHSA-2jr6-q4j9-8fvpGitHub2.2

In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass...

LOWAug 21, 2026View details →
GHSA-7fcf-m943-h7cxGitHub8.6

Authorization bypass through user-controlled key in Microsoft Partner Center allows an...

HIGHAug 21, 2026View details →
GHSA-j3r9-fw99-hv3rGitHub

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

UNKNOWNAug 21, 2026View details →
GHSA-m3qj-pp48-6w2pGitHub9.8

The customer update route in EverShop is declared with "access": "public" in packages/evershop...

CRITICALAug 21, 2026View details →
GHSA-hw2h-qf3m-2r8vGitHub6.4

Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from...

MEDIUMAug 21, 2026View details →
GHSA-r6q7-c86h-xxvpGitHub6.5

Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose...

MEDIUMAug 21, 2026View details →

Browse all advisories

Severity:
Loading…

Frequently asked questions

What is a vendor security advisory?
A vendor security advisory is an official disclosure published by the software or hardware vendor itself — Microsoft's MSRC, Red Hat Product Security, GitHub Security Advisories, and others. Vendor advisories typically include a CVE-ID once one is assigned, vendor-specific remediation steps, and the exact list of affected product builds — all of which the upstream NVD entry may not yet have.
How is this different from the NVD CVE feed?
NVD publishes CVEs after the CVE Numbering Authority coordinates disclosure with the vendor. Vendors often notify customers days to weeks before NVD's public record. This feed captures the vendor side directly, surfacing embargo-window disclosures that don't yet appear in NVD or GitHub Advisory Database.
Which vendors are tracked?
Ten vendors are live and ingesting today: GitHub Security Advisories (GHSA), Red Hat Product Security (RHSA via CSAF), Microsoft Security Response Center (MSRC), Cisco PSIRT, GitLab, AWS Security Bulletins, Palo Alto Networks, Google Cloud, HashiCorp, and Grafana Labs. OSV, Apple, Azure and Atlassian are registered but not yet ingesting. VMware (VMSA) is registered but dormant — Broadcom retired the public feed after the acquisition and has not replaced it.
How often is the feed updated?
GitHub GHSA and Cisco PSIRT are polled hourly for fast embargo-window coverage. Microsoft MSRC, AWS and Google Cloud are polled every two hours, Red Hat CSAF every three, and GitLab, Palo Alto, HashiCorp and Grafana every six. Those are poll floors, not a live stream — an advisory can sit at the vendor for up to one interval before we see it. Each advisory's first-seen timestamp is preserved separately from the vendor's published-at so you can audit how quickly we caught it.
Does the feed include CVSS scores and remediation guidance?
Yes when the vendor publishes them. CVSS v3 scores, severity bands (Critical/High/Medium/Low), the full list of affected product builds, vendor-specific patch / mitigation steps, and authoritative reference URLs are surfaced on every advisory detail page. Fields are blank when the vendor's own disclosure did not include them.
Is this feed free to use?
Yes. All pages on /pulse/vendor-advisories are free to read and link to. The underlying advisory data is published by each vendor under their own terms — EchelonGraph aggregates and normalises it for discoverability.