GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,582
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,162 advisories
Filter by severity
Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.
High
Unreviewed
CVE-2026-50344
was published
Jul 14, 2026
Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.
High
Unreviewed
CVE-2026-50346
was published
Jul 14, 2026
Improper authorization in Windows Admin Center allows an authorized attacker to execute code...
High
Unreviewed
CVE-2026-58631
was published
Jul 14, 2026
Insufficient granularity of access control in Windows StateRepository API allows an authorized...
High
Unreviewed
CVE-2026-49170
was published
Jul 14, 2026
A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function...
Moderate
Unreviewed
CVE-2026-15622
was published
Jul 14, 2026
Kimai: Improper Authorization in Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate Manipulation
Moderate
CVE-2026-52826
was published
for
kimai/kimai
(Composer)
Jul 14, 2026
Kimai has Improper Authorization in Team Member and Team Activity Assignment APIs Which Allows Expansion of Team Scope Beyond Authorized Visibility
Moderate
CVE-2026-52825
was published
for
kimai/kimai
(Composer)
Jul 14, 2026
Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access Revocation
Moderate
CVE-2026-52822
was published
for
kimai/kimai
(Composer)
Jul 14, 2026
Decidim: CSV census record endpoints improper authorization
Moderate
CVE-2026-45415
was published
for
decidim-verifications
(RubyGems)
Jul 13, 2026
A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5...
Low
Unreviewed
CVE-2026-15516
was published
Jul 13, 2026
Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO...
High
Unreviewed
CVE-2026-56313
was published
Jul 12, 2026
Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin...
High
Unreviewed
CVE-2026-56241
was published
Jul 12, 2026
Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid...
Moderate
Unreviewed
CVE-2026-56240
was published
Jul 11, 2026
tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies
Moderate
CVE-2026-49977
was published
for
tarteaucitronjs
(npm)
Jul 10, 2026
A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Affected by this issue is some...
Low
Unreviewed
CVE-2026-15318
was published
Jul 10, 2026
A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code...
Low
Unreviewed
CVE-2026-15191
was published
Jul 9, 2026
Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books
Moderate
CVE-2026-50554
was published
for
github.com/enchant97/note-mark/backend
(Go)
Jul 9, 2026
NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries
Moderate
CVE-2026-49463
was published
for
nl.nl-portal:besluiten
(Maven)
Jul 8, 2026
A vulnerability was determined in Harness up to 2.28.2. This vulnerability affects the function...
Low
Unreviewed
CVE-2026-15036
was published
Jul 8, 2026
Capgo before 12.128.2 contains a broken access control vulnerability in the organization...
High
Unreviewed
CVE-2026-56246
was published
Jul 8, 2026
Capgo before 12.128.2 contains an authorization flaw in transfer_app() that fails to update...
Moderate
Unreviewed
CVE-2026-56293
was published
Jul 8, 2026
@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
Moderate
GHSA-p2fr-6hmx-4528
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
High
CVE-2026-55428
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Coder: User-admin role can reset owner account password
High
CVE-2026-55077
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Duplicate Advisory: Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
Moderate
GHSA-rqjw-r5g4-x8qm
was published
for
craftcms/cms
(Composer)
Jul 6, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API