GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,170 advisories
Filter by severity
A weakness has been identified in Soarkey StudentManagement and 学生信息管理系统 up to...
Moderate
Unreviewed
CVE-2026-82621
was published
Aug 31, 2026
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects...
Moderate
Unreviewed
CVE-2026-82602
was published
Aug 31, 2026
Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function...
Moderate
Unreviewed
CVE-2026-82658
was published
Aug 30, 2026
Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation
High
CVE-2026-55212
was published
for
pimcore/studio-backend-bundle
(Composer)
Aug 28, 2026
Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration
Moderate
CVE-2026-55547
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key
High
CVE-2026-55065
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project
Moderate
CVE-2026-54766
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release...
Critical
Unreviewed
CVE-2026-16279
was published
Aug 27, 2026
Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing....
High
Unreviewed
CVE-2026-18985
was published
Aug 26, 2026
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions...
High
Unreviewed
CVE-2026-66422
was published
Aug 26, 2026
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
High
CVE-2026-55571
was published
for
djust
(pip)
Aug 25, 2026
A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function...
Moderate
Unreviewed
CVE-2026-78887
was published
Aug 25, 2026
Ech0 version 4.3.4 and earlier fails to reliably enforce scoped access token (least-privilege)...
High
Unreviewed
CVE-2026-79667
was published
Aug 25, 2026
A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects...
Low
Unreviewed
CVE-2026-78160
was published
Aug 24, 2026
A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0...
Low
Unreviewed
CVE-2026-78144
was published
Aug 24, 2026
A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0....
Low
Unreviewed
CVE-2026-78142
was published
Aug 24, 2026
Improper authorization for CRUD operations on Project Roles and Project Role permissions for...
High
Unreviewed
CVE-2026-66722
was published
Aug 21, 2026
django CMS: Structure endpoint bypasses page-view permission
Moderate
CVE-2026-54624
was published
for
django-cms
(pip)
Aug 20, 2026
Laravel Backpack CRUD: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDisk
High
CVE-2026-54178
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows...
Low
Unreviewed
CVE-2026-18283
was published
Aug 20, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege...
High
Unreviewed
CVE-2026-16925
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold...
High
Unreviewed
CVE-2026-76352
was published
Aug 20, 2026
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
High
GHSA-p77j-g7h5-r2vw
was published
for
geolens
(pip)
Aug 19, 2026
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
Moderate
CVE-2026-55236
was published
for
langgraph-api
(pip)
Aug 19, 2026
stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on...
Critical
Unreviewed
CVE-2026-76243
was published
Aug 19, 2026
ProTip!
Advisories are also available from the
GraphQL API