GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
384 advisories
Filter by severity
PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
High
CVE-2026-57121
was published
for
praisonai-platform
(pip)
Jun 18, 2026
@better-auth/sso: SSO provider may allow registration for any org member without a checking their role
High
CVE-2026-53515
was published
for
@better-auth/sso
(npm)
Jul 20, 2026
Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
High
CVE-2026-54012
was published
for
open-webui
(pip)
Jun 17, 2026
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
High
GHSA-x8mg-6r4p-87pf
was published
for
com.arcadedb:arcadedb-server
(Maven)
Jul 16, 2026
DevGuard has improper authorization on public assets
High
CVE-2026-48089
was published
for
github.com/l3montree-dev/devguard
(Go)
Jun 11, 2026
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-58277
was published
Jul 14, 2026
Improper authorization in Windows Installer allows an authorized attacker to elevate privileges...
High
Unreviewed
CVE-2026-58540
was published
Jul 14, 2026
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized...
High
Unreviewed
CVE-2026-54121
was published
Jul 14, 2026
Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.
High
Unreviewed
CVE-2026-50344
was published
Jul 14, 2026
Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.
High
Unreviewed
CVE-2026-50346
was published
Jul 14, 2026
Improper authorization in Windows Admin Center allows an authorized attacker to execute code...
High
Unreviewed
CVE-2026-58631
was published
Jul 14, 2026
Insufficient granularity of access control in Windows StateRepository API allows an authorized...
High
Unreviewed
CVE-2026-49170
was published
Jul 14, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
High
CVE-2024-29033
was published
for
oauthenticator
(pip)
Mar 20, 2024
Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO...
High
Unreviewed
CVE-2026-56313
was published
Jul 12, 2026
Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin...
High
Unreviewed
CVE-2026-56241
was published
Jul 12, 2026
Capgo before 12.128.2 contains a broken access control vulnerability in the organization...
High
Unreviewed
CVE-2026-56246
was published
Jul 8, 2026
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
High
CVE-2026-55428
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Coder: User-admin role can reset owner account password
High
CVE-2026-55077
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-58284
was published
Jul 3, 2026
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-57983
was published
Jul 3, 2026
Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap
High
CVE-2026-50279
was published
for
craftcms/cms
(Composer)
Jul 2, 2026
Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts...
High
Unreviewed
CVE-2026-56320
was published
Jul 1, 2026
Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation...
High
Unreviewed
CVE-2026-56249
was published
Jul 1, 2026
Improper Authorization vulnerability in Apache ActiveMQ.
An authenticated low-privilege Web...
High
Unreviewed
CVE-2026-49877
was published
Jun 30, 2026
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
High
Unreviewed
CVE-2026-45490
was published
Jun 9, 2026
ProTip!
Advisories are also available from the
GraphQL API