A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/
active 2024-09-21 → 2026-07-30 (UTC)
Activity over time
Daily event counts in the loaded window
Line chart, 678 days from 2024-09-21 to 2026-07-30. Pushes: 373 total, peak 15 in a day. Pull requests: 184 total, peak 10 in a day. Issues: 200 total, peak 13 in a day. Comments: 508 total, peak 12 in a day. Stars: 68 total, peak 5 in a day.
- Pushes
- Pull requests
- Issues
- Comments
- Stars
Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.
Top contributors
Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity
| Contributor | Contributions | Pushes | PRs | Comments |
|---|---|---|---|---|
| TG1999 | 423 | 206 | 46 | 61 |
| keshav-space | 295 | 132 | 31 | 77 |
| ziadhany | 172 | 6 | 16 | 97 |
| pombredanne | 116 | 6 | 1 | 47 |
| Rishi-source | 73 | 0 | 19 | 41 |
| michaelehab | 44 | 10 | 9 | 10 |
| Dedsec0098 | 30 | 0 | 8 | 19 |
| DennisClark | 25 | 5 | 1 | 13 |
| Samk1710 | 24 | 0 | 0 | 12 |
| tdruez | 22 | 0 | 0 | 13 |
| kunalsz | 21 | 0 | 10 | 9 |
| NucleiAv | 12 | 0 | 3 | 6 |
| dependabot[bot] | 12 | 4 | 8 | 0 |
| mjherzog | 8 | 1 | 0 | 5 |
| armijnhemel | 8 | 0 | 0 | 4 |
| Copilot | 7 | 0 | 0 | 6 |
| Adityakk9031 | 7 | 0 | 4 | 3 |
| paarthbhatt | 6 | 0 | 2 | 3 |
| saransh1307 | 5 | 0 | 2 | 3 |
| unibik | 5 | 0 | 2 | 3 |
Recent activity
Latest issues, pull requests and releases
- Issue#1410pombredanne2026-06-16 22:38Add Liferay advisories
- Issue#1410pombredanne2026-06-16 22:38Add Liferay advisories
- Issue comment#1723ziadhany2026-05-14 23:45fedcode-next: Code pipeline and models to continuously collect scripts and vulnerability scanner rules to detect if the vulnerability is "expressed"
- Issue#1362ziadhany2026-05-14 21:54Add glibc advisories
- Issue#2303pombredanne2026-05-14 15:33Find a scalable way to archive reference URLS
- Pull request#2301TG19992026-05-09 19:52
- Issue comment#2280kx7m2qd2026-05-02 13:22apache_kafka_importer_v2 import error
- Issue comment#2257TG19992026-05-01 08:25Refactor doc to restructure and improve #1943
- Issue comment#1836kx7m2qd2026-05-01 04:13Schneider Electric advisories
- Issue comment#2272keshav-space2026-04-15 18:53Malformed aliases and AVID in the Alpine V2 advisory
- Releasegithub-actions[bot]2026-04-10 15:54v38.4.0
- Issue#2244TG19992026-04-10 07:43Calculate weighted_severity, exploitibility and risk score for a AdvisorySet
- Issue comment#2244TG19992026-04-10 07:43Calculate weighted_severity, exploitibility and risk score for a AdvisorySet
- Issue#1727TG19992026-04-09 10:01fedcode-next: Collect additional data to support automated curation of vulnerability data
- Releasegithub-actions[bot]2026-04-08 14:11v38.3.0
- Releasegithub-actions[bot]2026-04-08 13:31v38.2.0
- Pull request#2258heliocastro2026-04-08 13:18
- Pull request#2256keshav-space2026-04-07 13:32
- Issue#2057TG19992026-04-07 09:16Review the API structure for advisories
- Issue#2057TG19992026-04-07 09:16Review the API structure for advisories
- Issue#2057TG19992026-04-07 09:15Review the API structure for advisories
- Issue comment#2248Sanjay-VK072026-04-02 04:24fix: truncate long reference_id to avoid DB DataError
- Pull request#2248Sanjay-VK072026-04-02 04:08
- Pull request#2246abhey82026-03-31 04:31
- Issue comment#2228shivamshrma092026-03-28 05:43Enhance advisory grouping 2172
Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 68 stars here means stars gained during the window, not the repo's star count.