GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
569 advisories
Filter by severity
@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
Moderate
GHSA-p2fr-6hmx-4528
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
Duplicate Advisory: Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
Moderate
GHSA-rqjw-r5g4-x8qm
was published
for
craftcms/cms
(Composer)
Jul 6, 2026
•
withdrawn
A vulnerability was detected in mjperpinosa stumasy up to...
Moderate
Unreviewed
CVE-2026-14753
was published
Jul 5, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
Moderate
CVE-2026-50201
was published
for
Steeltoe.Management.Endpoint
(NuGet)
Jul 2, 2026
Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API
Moderate
GHSA-q4rm-m6xh-5pv7
was published
for
froxlor/froxlor
(Composer)
Jul 2, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
Moderate
CVE-2026-49997
was published
for
surrealdb
(Rust)
Jul 1, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
Moderate
GHSA-f82j-v89j-mf86
was published
for
surrealdb
(Rust)
Jul 1, 2026
n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users...
Moderate
Unreviewed
CVE-2026-56350
was published
Jul 1, 2026
Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for...
Moderate
Unreviewed
CVE-2026-55956
was published
Jun 29, 2026
OpenAM OAuth Authorization Bypass via PKCE Challenge
Moderate
CVE-2026-48717
was published
for
org.openidentityplatform.openam:openam-oauth2
(Maven)
Jun 29, 2026
A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This...
Moderate
Unreviewed
CVE-2026-13490
was published
Jun 28, 2026
@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets
Moderate
CVE-2026-46700
was published
for
@actual-app/sync-server
(npm)
Jun 22, 2026
Capgo before 12.128.2 contains an authorization bypass vulnerability in webhook management...
Moderate
Unreviewed
CVE-2026-56295
was published
Jun 20, 2026
Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability...
Moderate
Unreviewed
CVE-2026-12673
was published
Jun 20, 2026
OpenClaw: Slack reaction events could ignore reaction notification settings
Moderate
CVE-2026-53851
was published
for
openclaw
(npm)
Jun 18, 2026
NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)
Moderate
CVE-2026-54683
was published
for
nl.nl-portal:documenten-api
(Maven)
Jun 18, 2026
A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function...
Moderate
Unreviewed
CVE-2026-12204
was published
Jun 15, 2026
A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability...
Moderate
Unreviewed
CVE-2026-12190
was published
Jun 15, 2026
Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
Moderate
CVE-2026-49397
was published
for
github.com/nezhahq/nezha
(Go)
Jun 10, 2026
Hono: JWT middleware accepts any Authorization scheme, not only Bearer
Moderate
CVE-2026-47673
was published
for
hono
(npm)
Jun 4, 2026
An improper authorization vulnerability has been identified in Apache Kafka.
The implementation...
Moderate
Unreviewed
CVE-2026-41115
was published
Jun 2, 2026
Apache ActiveMQ server has an incomplete authorization workflow
Moderate
CVE-2026-46605
was published
for
org.apache.activemq:apache-activemq
(Maven)
Jun 1, 2026
A vulnerability has been found in Dolibarr ERP CRM 23.0.0/23.0.1/23.0.2. The affected element is...
Moderate
Unreviewed
CVE-2026-10154
was published
May 31, 2026
SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical...
Moderate
Unreviewed
CVE-2025-68712
was published
May 27, 2026
IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote...
Moderate
Unreviewed
CVE-2026-6938
was published
May 27, 2026
ProTip!
Advisories are also available from the
GraphQL API