Vendor Security Advisories

Security advisories straight from the source — GitHub, Red Hat, Microsoft, Cisco and beyond. Searchable, indexed, and polled hourly, with the time we first saw each one recorded on the advisory.

Live98,968 advisories tracked844 disclosed before NVD9,200 Critical46,045 High29,513 Medium4,550 Low
10 vendors tracked· 20,113 ingested in last 24h← Back to CVE Pulse

🔔 Vendor advisory alerts

Catch vendor-disclosed advisories the day they ship

Vendors like Microsoft, Red Hat, and GitHub publish security advisories days to weeks before NVD assigns a CVE. Subscribe to get these the moment we ingest them.

  • ✓Microsoft MSRC, Red Hat RHSA, GitHub GHSA — full vendor coverage
  • ✓Embargo-window disclosures included (Pre-CVE advisories)
  • ✓Real-time, daily, weekly, or monthly cadence

Free · Unsubscribe in one click · No marketing email

Browse by vendor

10 active · 10 tracked
Disclosed before NVD assigned a CVE-ID844 total

These advisories were published by the upstream vendor before NVD assigned a CVE-ID. Customers received the email on day zero — everyone else has to wait days to weeks for NVD to catch up.

GHSA-x8gv-g2g3-65fjGitHub8.2

SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)

HIGHOct 2, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-p23f-cm6q-2qp8GitHub5.7

SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)

MEDIUMOct 2, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-mwm8-39rw-8826GitHub

sqlite3-ruby: Use-After-Free in SQLite Aggregate Arguments in Heap-Allocated Argument Array

MEDIUMOct 2, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-cjcg-cxmh-9wcrGitHub7.5

Praxis affected by HTTP/2 Bomb

HIGHOct 2, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-fj2x-mqqp-3v2wGitHub5.5

Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values

MEDIUMOct 2, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-v2f8-6655-7grjGitHub10.0

Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain

CRITICALOct 2, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-5rmq-chc7-m22fGitHub7.5

Vibe-Trading file-read tools expose arbitrary server-readable files

HIGHOct 2, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-jqmf-mx4f-hfr6GitHub10.0

Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF

CRITICALOct 2, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-4672-hwv6-gq62GitHub5.4

Trigger.dev: Cross-environment deployment cancel

MEDIUMOct 2, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-9q4r-4842-93vwGitHub7.7

Trigger.dev: Cross-tenant SQL injection in the TSQL query compiler (POST /api/v1/query) via unsanitized window-function name

HIGHOct 2, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-59h8-w5q6-mfmpGitHub5.3

Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId

MEDIUMOct 2, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-pqxw-g93w-hj9xGitHub

Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise

HIGHOct 2, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
Most Recent Vendor Advisoriestop 12

The newest 12 advisories ingested from any tracked vendor — refreshed every two minutes.

RHSA-2026:75579Red Hat7.8

Red Hat Security Advisory: sudo security update

HIGHOct 5, 2026View details →
RHSA-2026:75582Red Hat6.5

Red Hat Security Advisory: librabbitmq security update

HIGHOct 5, 2026View details →
GHSA-3r5w-f4x9-pgqvGitHub7.3

A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0....

MEDIUMOct 5, 2026View details →
GHSA-r8wv-hwwh-9qggGitHub7.3

A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element...

MEDIUMOct 5, 2026View details →
GHSA-f92j-xqqj-522rGitHub

In venc, there is a possible out of bounds write due to type confusion. This could lead to local...

UNKNOWNOct 5, 2026View details →
GHSA-36fv-c8f2-wfmcGitHub7.3

A security vulnerability has been detected in itsourcecode Online Admission System 1.0. The...

MEDIUMOct 5, 2026View details →
GHSA-pgv8-fxqg-qhf2GitHub6.3

A vulnerability was identified in itsourcecode Online Admission System 1.0. This issue affects...

LOWOct 5, 2026View details →
GHSA-7hfg-hgrm-p26mGitHub

In display, there is a possible out of bounds write due to a missing bounds check. This could...

UNKNOWNOct 5, 2026View details →
GHSA-5fq6-5rjv-rwvvGitHub

In apu, there is a possible application crash due to double free. This could lead to local denial...

UNKNOWNOct 5, 2026View details →
GHSA-4j3w-6745-4v34GitHub

In Modem, there is a possible system crash due to a missing bounds check. This could lead to...

UNKNOWNOct 5, 2026View details →
GHSA-vv5q-53j2-fq73GitHub

In Modem, there is a possible out of bounds read due to an incorrect bounds check. This could...

UNKNOWNOct 5, 2026View details →
GHSA-g76f-499r-45ccGitHub

In display, there is a possible escalation of privilege due to an integer overflow. This could...

UNKNOWNOct 5, 2026View details →

Browse all advisories

Severity:
Loading…

Frequently asked questions

What is a vendor security advisory?
A vendor security advisory is an official disclosure published by the software or hardware vendor itself — Microsoft's MSRC, Red Hat Product Security, GitHub Security Advisories, and others. Vendor advisories typically include a CVE-ID once one is assigned, vendor-specific remediation steps, and the exact list of affected product builds — all of which the upstream NVD entry may not yet have.
How is this different from the NVD CVE feed?
NVD publishes CVEs after the CVE Numbering Authority coordinates disclosure with the vendor. Vendors often notify customers days to weeks before NVD's public record. This feed captures the vendor side directly, surfacing embargo-window disclosures that don't yet appear in NVD or GitHub Advisory Database.
Which vendors are tracked?
Ten vendors are live and ingesting today: GitHub Security Advisories (GHSA), Red Hat Product Security (RHSA via CSAF), Microsoft Security Response Center (MSRC), Cisco PSIRT, GitLab, AWS Security Bulletins, Palo Alto Networks, Google Cloud, HashiCorp, and Grafana Labs. OSV, Apple, Azure and Atlassian are registered but not yet ingesting. VMware (VMSA) is registered but dormant — Broadcom retired the public feed after the acquisition and has not replaced it.
How often is the feed updated?
GitHub GHSA and Cisco PSIRT are polled hourly for fast embargo-window coverage. Microsoft MSRC, AWS and Google Cloud are polled every two hours, Red Hat CSAF every three, and GitLab, Palo Alto, HashiCorp and Grafana every six. Those are poll floors, not a live stream — an advisory can sit at the vendor for up to one interval before we see it. Each advisory's first-seen timestamp is preserved separately from the vendor's published-at so you can audit how quickly we caught it.
Does the feed include CVSS scores and remediation guidance?
Yes when the vendor publishes them. CVSS v3 scores, severity bands (Critical/High/Medium/Low), the full list of affected product builds, vendor-specific patch / mitigation steps, and authoritative reference URLs are surfaced on every advisory detail page. Fields are blank when the vendor's own disclosure did not include them.
Is this feed free to use?
Yes. All pages on /pulse/vendor-advisories are free to read and link to. The underlying advisory data is published by each vendor under their own terms — EchelonGraph aggregates and normalises it for discoverability.