Vendor Security Advisories
Security advisories straight from the source — Microsoft, Red Hat, GitHub, and beyond. Searchable, indexed, and live the moment vendors publish.
🔔 Vendor advisory alerts
Catch vendor-disclosed advisories the day they ship
Vendors like Microsoft, Red Hat, and GitHub publish security advisories days to weeks before NVD assigns a CVE. Subscribe to get these the moment we ingest them.
- ✓Microsoft MSRC, Red Hat RHSA, GitHub GHSA — full vendor coverage
- ✓Embargo-window disclosures included (Pre-CVE advisories)
- ✓Real-time, daily, weekly, or monthly cadence
Browse by vendor
7 active · 14 trackedMost Recent Vendor Advisoriestop 12
The newest 12 advisories ingested from any tracked vendor — refreshed every two minutes.
CVE-2026-9291 - Insecure Deserialization in Amazon Braket SDK Job Results Processing
Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance
aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler
qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set
FileBrowser Quantum: Path traversal in public share PATCH allows file ops outside shared directory
CVE-2026-9255 - Tool Execution Without Authorization via Piped Stdin in Kiro CLI
YesWiki: Unauthenticated SQL Injection
ImageMagick: Heap Buffer Over-Read in distributed pixel cache server
ImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication model
ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking
ImageMagick: Heap Buffer Over-Write in distributed pixel cache server
The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...