GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
384 advisories
Filter by severity
Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation
High
CVE-2026-55212
was published
for
pimcore/studio-backend-bundle
(Composer)
Aug 28, 2026
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key
High
CVE-2026-55065
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing....
High
Unreviewed
CVE-2026-18985
was published
Aug 26, 2026
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions...
High
Unreviewed
CVE-2026-66422
was published
Aug 26, 2026
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
High
CVE-2026-55571
was published
for
djust
(pip)
Aug 25, 2026
Ech0 version 4.3.4 and earlier fails to reliably enforce scoped access token (least-privilege)...
High
Unreviewed
CVE-2026-79667
was published
Aug 25, 2026
Improper authorization for CRUD operations on Project Roles and Project Role permissions for...
High
Unreviewed
CVE-2026-66722
was published
Aug 21, 2026
Laravel Backpack CRUD: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDisk
High
CVE-2026-54178
was published
for
backpack/crud
(Composer)
Aug 20, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege...
High
Unreviewed
CVE-2026-16925
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold...
High
Unreviewed
CVE-2026-76352
was published
Aug 20, 2026
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
High
GHSA-p77j-g7h5-r2vw
was published
for
geolens
(pip)
Aug 19, 2026
This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0...
High
Unreviewed
CVE-2026-21584
was published
Aug 19, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass...
High
Unreviewed
CVE-2026-16879
was published
Aug 14, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege...
High
Unreviewed
CVE-2026-18509
was published
Aug 13, 2026
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation...
High
Unreviewed
CVE-2026-10543
was published
Aug 12, 2026
Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements...
High
Unreviewed
CVE-2026-72786
was published
Aug 12, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege...
High
Unreviewed
CVE-2026-18499
was published
Aug 12, 2026
Winter: Authenticated backend users can bypass Users controller permission checks
High
CVE-2026-35445
was published
for
winter/wn-backend-module
(Composer)
Aug 12, 2026
Craft CMS: Arbitrary user password reset leading to administrator account takeover
High
GHSA-p8x7-9vfw-p7vc
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
High
CVE-2026-70472
was published
for
flowise
(npm)
Aug 4, 2026
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
High
CVE-2026-43983
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Jul 28, 2026
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
High
GHSA-pvcr-8mvp-w8qr
was published
for
@budibase/server
(npm)
Jul 24, 2026
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
High
CVE-2026-64642
was published
for
next
(npm)
Jul 22, 2026
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
High
CVE-2026-58424
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
@better-auth/sso: SSO provider may allow registration for any org member without a checking their role
High
CVE-2026-53515
was published
for
@better-auth/sso
(npm)
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API