GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
384 advisories
Filter by severity
Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
High
CVE-2026-45337
was published
for
better-auth
(npm)
Jun 4, 2026
nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator
High
CVE-2026-47726
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 8, 2026
Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges...
High
Unreviewed
CVE-2026-42902
was published
Jun 9, 2026
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose...
High
Unreviewed
CVE-2026-45503
was published
Jun 9, 2026
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
High
Unreviewed
CVE-2026-45490
was published
Jun 9, 2026
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute...
High
Unreviewed
CVE-2026-47298
was published
Jun 9, 2026
Dex: Token-exchange endpoint is missing AllowedConnectors enforcement
High
GHSA-7qjx-gp9h-65qj
was published
for
github.com/dexidp/dex
(Go)
Jun 9, 2026
A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user...
High
Unreviewed
CVE-2026-47342
was published
Jun 11, 2026
DevGuard has improper authorization on public assets
High
CVE-2026-48089
was published
for
github.com/l3montree-dev/devguard
(Go)
Jun 11, 2026
Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
High
CVE-2026-54012
was published
for
open-webui
(pip)
Jun 17, 2026
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view...
High
Unreviewed
CVE-2026-20190
was published
Jun 17, 2026
PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
High
CVE-2026-57121
was published
for
praisonai-platform
(pip)
Jun 18, 2026
OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC
High
CVE-2026-45048
was published
for
org.openidentityplatform.openam:openam-core
(Maven)
Jun 23, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)
High
CVE-2026-49338
was published
for
go.senan.xyz/gonic
(Go)
Jun 26, 2026
Improper Authorization vulnerability in Apache ActiveMQ.
An authenticated low-privilege Web...
High
Unreviewed
CVE-2026-49877
was published
Jun 30, 2026
Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation...
High
Unreviewed
CVE-2026-56249
was published
Jul 1, 2026
Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts...
High
Unreviewed
CVE-2026-56320
was published
Jul 1, 2026
Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap
High
CVE-2026-50279
was published
for
craftcms/cms
(Composer)
Jul 2, 2026
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-57983
was published
Jul 3, 2026
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-58284
was published
Jul 3, 2026
Coder: User-admin role can reset owner account password
High
CVE-2026-55077
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
High
CVE-2026-55428
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Capgo before 12.128.2 contains a broken access control vulnerability in the organization...
High
Unreviewed
CVE-2026-56246
was published
Jul 8, 2026
Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin...
High
Unreviewed
CVE-2026-56241
was published
Jul 12, 2026
Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO...
High
Unreviewed
CVE-2026-56313
was published
Jul 12, 2026
ProTip!
Advisories are also available from the
GraphQL API