GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,582
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
119 advisories
Filter by severity
An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release...
Critical
Unreviewed
CVE-2026-16279
was published
Aug 27, 2026
stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on...
Critical
Unreviewed
CVE-2026-76243
was published
Aug 19, 2026
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
Critical
GHSA-m5w8-4gq2-6f8x
was published
for
vm2
(npm)
Aug 17, 2026
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate...
Critical
Unreviewed
CVE-2026-59118
was published
Aug 7, 2026
A privilege escalation vulnerability allows local users to execute arbitrary code as root via...
Critical
Unreviewed
CVE-2026-18367
was published
Aug 7, 2026
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
Critical
CVE-2026-73644
was published
for
org.openidentityplatform.opendj:opendj-server-legacy
(Maven)
Jul 24, 2026
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information...
Critical
Unreviewed
CVE-2026-62835
was published
Jul 24, 2026
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate...
Critical
Unreviewed
CVE-2026-56160
was published
Jul 24, 2026
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
Critical
CVE-2026-73421
was published
for
next-auth
(npm)
Jul 23, 2026
SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group...
Critical
Unreviewed
CVE-2026-28312
was published
Jul 21, 2026
IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected...
Critical
Unreviewed
CVE-2026-7663
was published
Jun 30, 2026
Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise
Critical
CVE-2026-55166
was published
for
lemur
(pip)
Jun 25, 2026
OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints
Critical
CVE-2026-45052
was published
for
org.openidentityplatform.openam:openam-federation-library
(Maven)
Jun 24, 2026
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass...
Critical
Unreviewed
CVE-2026-10580
was published
Jun 5, 2026
Shopper: Authorization bypass and RBAC privilege escalation in team settings
Critical
CVE-2026-47744
was published
for
shopper/framework
(Composer)
Jun 5, 2026
Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose...
Critical
Unreviewed
CVE-2026-48579
was published
Jun 5, 2026
In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a...
Critical
Unreviewed
CVE-2026-0072
was published
Jun 1, 2026
stigmem-node: Auth-disabled deployments may grant broad anonymous access outside loopback
Critical
GHSA-fp6w-8wpg-74g5
was published
for
stigmem-node
(pip)
May 29, 2026
Apache Tomcat - Security constraints not correctly applied
Critical
CVE-2026-43515
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
May 12, 2026
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information...
Critical
Unreviewed
CVE-2026-33823
was published
May 8, 2026
The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP...
Critical
Unreviewed
CVE-2026-30496
was published
May 7, 2026
Paperclip: Cross-tenant agent API token minting via missing assertCompanyAccess on /api/agents/:id/keys
Critical
GHSA-47wq-cj9q-wpmp
was published
for
@paperclipai/server
(npm)
Apr 16, 2026
Juju: CloudSpec method leaking cloud credentials
Critical
CVE-2026-5412
was published
for
github.com/juju/juju
(Go)
Apr 10, 2026
Signal K Server: Privilege Escalation by Admin Role Injection via /enableSecurity
Critical
CVE-2026-33950
was published
for
signalk-server
(npm)
Apr 3, 2026
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges...
Critical
Unreviewed
CVE-2026-32213
was published
Apr 3, 2026
ProTip!
Advisories are also available from the
GraphQL API