GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,582
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,162 advisories
Filter by severity
An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release...
Critical
Unreviewed
CVE-2026-16279
was published
Aug 27, 2026
Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing....
High
Unreviewed
CVE-2026-18985
was published
Aug 26, 2026
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions...
High
Unreviewed
CVE-2026-66422
was published
Aug 26, 2026
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
High
CVE-2026-55571
was published
for
djust
(pip)
Aug 25, 2026
A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function...
Moderate
Unreviewed
CVE-2026-78887
was published
Aug 25, 2026
Ech0 version 4.3.4 and earlier fails to reliably enforce scoped access token (least-privilege)...
High
Unreviewed
CVE-2026-79667
was published
Aug 25, 2026
A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects...
Low
Unreviewed
CVE-2026-78160
was published
Aug 24, 2026
A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0...
Low
Unreviewed
CVE-2026-78144
was published
Aug 24, 2026
A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0....
Low
Unreviewed
CVE-2026-78142
was published
Aug 24, 2026
Improper authorization for CRUD operations on Project Roles and Project Role permissions for...
High
Unreviewed
CVE-2026-66722
was published
Aug 21, 2026
django CMS: Structure endpoint bypasses page-view permission
Moderate
CVE-2026-54624
was published
for
django-cms
(pip)
Aug 20, 2026
Laravel Backpack CRUD: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDisk
High
CVE-2026-54178
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows...
Low
Unreviewed
CVE-2026-18283
was published
Aug 20, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege...
High
Unreviewed
CVE-2026-16925
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold...
High
Unreviewed
CVE-2026-76352
was published
Aug 20, 2026
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
High
GHSA-p77j-g7h5-r2vw
was published
for
geolens
(pip)
Aug 19, 2026
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
Moderate
CVE-2026-55236
was published
for
langgraph-api
(pip)
Aug 19, 2026
stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on...
Critical
Unreviewed
CVE-2026-76243
was published
Aug 19, 2026
The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-11729
was published
Aug 19, 2026
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web...
Moderate
Unreviewed
CVE-2026-70923
was published
Aug 18, 2026
A flaw was found in the group policy provider of Keycloak authorization services, which is used...
Moderate
Unreviewed
CVE-2026-19608
was published
Aug 18, 2026
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
Critical
GHSA-m5w8-4gq2-6f8x
was published
for
vm2
(npm)
Aug 17, 2026
A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some...
Low
Unreviewed
CVE-2026-19997
was published
Aug 17, 2026
A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown...
Low
Unreviewed
CVE-2026-19994
was published
Aug 17, 2026
A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300,...
Moderate
Unreviewed
CVE-2026-19979
was published
Aug 17, 2026
ProTip!
Advisories are also available from the
GraphQL API