Vendor Security Advisories

Security advisories straight from the source — GitHub, Red Hat, Microsoft, Cisco and beyond. Searchable, indexed, and polled hourly, with the time we first saw each one recorded on the advisory.

Live72,815 advisories tracked716 disclosed before NVD6,964 Critical34,167 High23,087 Medium3,574 Low
10 vendors tracked· 461 ingested in last 24h← Back to CVE Pulse

🔔 Vendor advisory alerts

Catch vendor-disclosed advisories the day they ship

Vendors like Microsoft, Red Hat, and GitHub publish security advisories days to weeks before NVD assigns a CVE. Subscribe to get these the moment we ingest them.

  • Microsoft MSRC, Red Hat RHSA, GitHub GHSA — full vendor coverage
  • Embargo-window disclosures included (Pre-CVE advisories)
  • Real-time, daily, weekly, or monthly cadence

Free · Unsubscribe in one click · No marketing email

Browse by vendor

10 active · 10 tracked
Disclosed before NVD assigned a CVE-ID716 total

These advisories were published by the upstream vendor before NVD assigned a CVE-ID. Customers received the email on day zero — everyone else has to wait days to weeks for NVD to catch up.

GHSA-jgh3-fggc-mcpmGitHub7.6

Obot: Server-Side Request Forgery via remote MCP server URL

HIGHSep 18, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-pr6h-vr44-xq8jGitHub5.3

Obot: MCP Registry API readable without authentication

MEDIUMSep 18, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-xwmw-prc4-v3crGitHub8.8

Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion

HIGHSep 18, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-39wr-7q6h-cf68GitHub7.5

LMDeploy has an SSRF bypass

HIGHSep 18, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-jr78-w6w5-m8f8GitHub7.3

Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks

HIGHSep 18, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-9rcc-pmj8-ffhrGitHub6.1

Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)

MEDIUMSep 18, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-xjw9-38cr-6372GitHub

djust: A template binding inherits a context safety grant it never earned (XSS)

HIGHSep 17, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-9395-2g46-rj3fGitHub

djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)

HIGHSep 17, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
CVE-2026-76154Grafana

Geomap MapLibre XSS

UNKNOWNSep 17, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-5648-rgj9-v224GitHub8.1

@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS

HIGHSep 15, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-rf68-8gjr-36q7GitHub

Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty

LOWSep 15, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-2xmm-m4wv-3fjhGitHub3.9

October CMS: Incomplete Scheme Validation in Image Resizer

LOWSep 14, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
Most Recent Vendor Advisoriestop 12

The newest 12 advisories ingested from any tracked vendor — refreshed every two minutes.

GHSA-53vp-fjc5-cqj6GitHub5.3

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for...

MEDIUMSep 19, 2026View details →
GHSA-mff9-5jrw-3j2mGitHub6.1

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to...

MEDIUMSep 19, 2026View details →
GHSA-4f44-p79q-6vj4GitHub6.5

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for...

MEDIUMSep 19, 2026View details →
GHSA-95p6-v6qj-q4v6GitHub4.3

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to...

MEDIUMSep 19, 2026View details →
GHSA-fjhh-mxpw-32j7GitHub6.5

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to...

MEDIUMSep 19, 2026View details →
GHSA-54jx-f43m-h839GitHub6.1

The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword...

MEDIUMSep 19, 2026View details →
GHSA-3fg9-62hh-37mhGitHub8.8

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function...

HIGHSep 19, 2026View details →
GHSA-2vrv-wr6r-v79vGitHub9.1

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress...

CRITICALSep 19, 2026View details →
GHSA-x57m-9xmj-gh9pGitHub9.1

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all...

CRITICALSep 19, 2026View details →
GHSA-hcxp-7h6p-263rGitHub6.5

The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in...

MEDIUMSep 19, 2026View details →
GHSA-79fj-jcjp-5w4vGitHub6.4

The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty'...

MEDIUMSep 19, 2026View details →
GHSA-q642-cfr5-5536GitHub4.3

The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to,...

MEDIUMSep 19, 2026View details →

Browse all advisories

Severity:
Loading…

Frequently asked questions

What is a vendor security advisory?
A vendor security advisory is an official disclosure published by the software or hardware vendor itself — Microsoft's MSRC, Red Hat Product Security, GitHub Security Advisories, and others. Vendor advisories typically include a CVE-ID once one is assigned, vendor-specific remediation steps, and the exact list of affected product builds — all of which the upstream NVD entry may not yet have.
How is this different from the NVD CVE feed?
NVD publishes CVEs after the CVE Numbering Authority coordinates disclosure with the vendor. Vendors often notify customers days to weeks before NVD's public record. This feed captures the vendor side directly, surfacing embargo-window disclosures that don't yet appear in NVD or GitHub Advisory Database.
Which vendors are tracked?
Ten vendors are live and ingesting today: GitHub Security Advisories (GHSA), Red Hat Product Security (RHSA via CSAF), Microsoft Security Response Center (MSRC), Cisco PSIRT, GitLab, AWS Security Bulletins, Palo Alto Networks, Google Cloud, HashiCorp, and Grafana Labs. OSV, Apple, Azure and Atlassian are registered but not yet ingesting. VMware (VMSA) is registered but dormant — Broadcom retired the public feed after the acquisition and has not replaced it.
How often is the feed updated?
GitHub GHSA and Cisco PSIRT are polled hourly for fast embargo-window coverage. Microsoft MSRC, AWS and Google Cloud are polled every two hours, Red Hat CSAF every three, and GitLab, Palo Alto, HashiCorp and Grafana every six. Those are poll floors, not a live stream — an advisory can sit at the vendor for up to one interval before we see it. Each advisory's first-seen timestamp is preserved separately from the vendor's published-at so you can audit how quickly we caught it.
Does the feed include CVSS scores and remediation guidance?
Yes when the vendor publishes them. CVSS v3 scores, severity bands (Critical/High/Medium/Low), the full list of affected product builds, vendor-specific patch / mitigation steps, and authoritative reference URLs are surfaced on every advisory detail page. Fields are blank when the vendor's own disclosure did not include them.
Is this feed free to use?
Yes. All pages on /pulse/vendor-advisories are free to read and link to. The underlying advisory data is published by each vendor under their own terms — EchelonGraph aggregates and normalises it for discoverability.