GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
384 advisories
Filter by severity
SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE,...
High
Unreviewed
CVE-2024-58367
was published
Jul 18, 2026
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
High
GHSA-x8mg-6r4p-87pf
was published
for
com.arcadedb:arcadedb-server
(Maven)
Jul 16, 2026
Improper authorization in Windows Installer allows an authorized attacker to elevate privileges...
High
Unreviewed
CVE-2026-58540
was published
Jul 14, 2026
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-58277
was published
Jul 14, 2026
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized...
High
Unreviewed
CVE-2026-54121
was published
Jul 14, 2026
Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.
High
Unreviewed
CVE-2026-50344
was published
Jul 14, 2026
Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.
High
Unreviewed
CVE-2026-50346
was published
Jul 14, 2026
Improper authorization in Windows Admin Center allows an authorized attacker to execute code...
High
Unreviewed
CVE-2026-58631
was published
Jul 14, 2026
Insufficient granularity of access control in Windows StateRepository API allows an authorized...
High
Unreviewed
CVE-2026-49170
was published
Jul 14, 2026
Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO...
High
Unreviewed
CVE-2026-56313
was published
Jul 12, 2026
Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin...
High
Unreviewed
CVE-2026-56241
was published
Jul 12, 2026
Capgo before 12.128.2 contains a broken access control vulnerability in the organization...
High
Unreviewed
CVE-2026-56246
was published
Jul 8, 2026
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
High
CVE-2026-55428
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Coder: User-admin role can reset owner account password
High
CVE-2026-55077
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-58284
was published
Jul 3, 2026
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-57983
was published
Jul 3, 2026
Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap
High
CVE-2026-50279
was published
for
craftcms/cms
(Composer)
Jul 2, 2026
Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts...
High
Unreviewed
CVE-2026-56320
was published
Jul 1, 2026
Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation...
High
Unreviewed
CVE-2026-56249
was published
Jul 1, 2026
Improper Authorization vulnerability in Apache ActiveMQ.
An authenticated low-privilege Web...
High
Unreviewed
CVE-2026-49877
was published
Jun 30, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)
High
CVE-2026-49338
was published
for
go.senan.xyz/gonic
(Go)
Jun 26, 2026
OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC
High
CVE-2026-45048
was published
for
org.openidentityplatform.openam:openam-core
(Maven)
Jun 23, 2026
PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
High
CVE-2026-57121
was published
for
praisonai-platform
(pip)
Jun 18, 2026
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view...
High
Unreviewed
CVE-2026-20190
was published
Jun 17, 2026
Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
High
CVE-2026-54012
was published
for
open-webui
(pip)
Jun 17, 2026
ProTip!
Advisories are also available from the
GraphQL API