GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
566 advisories
Filter by severity
Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration
Moderate
CVE-2026-55547
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project
Moderate
CVE-2026-54766
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function...
Moderate
Unreviewed
CVE-2026-78887
was published
Aug 25, 2026
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web...
Moderate
Unreviewed
CVE-2026-70923
was published
Aug 18, 2026
django CMS: Structure endpoint bypasses page-view permission
Moderate
CVE-2026-54624
was published
for
django-cms
(pip)
Aug 20, 2026
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
Moderate
CVE-2026-55236
was published
for
langgraph-api
(pip)
Aug 19, 2026
The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-11729
was published
Aug 19, 2026
A flaw was found in the group policy provider of Keycloak authorization services, which is used...
Moderate
Unreviewed
CVE-2026-19608
was published
Aug 18, 2026
An authorization issue was addressed with improved state management. This issue is fixed in iOS...
Moderate
Unreviewed
CVE-2026-64743
was published
Jul 27, 2026
A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300,...
Moderate
Unreviewed
CVE-2026-19979
was published
Aug 17, 2026
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-3835
was published
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security...
Moderate
Unreviewed
CVE-2026-18144
was published
Aug 12, 2026
Calico's apiserver wraps tier-scoped resources so that every operation runs through...
Moderate
Unreviewed
CVE-2026-41187
was published
Jul 30, 2026
An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql...
Moderate
Unreviewed
CVE-2026-14538
was published
Jul 31, 2026
A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0....
Moderate
Unreviewed
CVE-2026-19064
was published
Aug 7, 2026
A vulnerability was identified in SourceCodester Online Examination & Learning Management System...
Moderate
Unreviewed
CVE-2026-19066
was published
Aug 7, 2026
Duplicate Advisory: Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
Moderate
GHSA-rqjw-r5g4-x8qm
was published
for
craftcms/cms
(Composer)
Jul 6, 2026
•
withdrawn
An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user...
Moderate
Unreviewed
CVE-2026-23981
was published
Jul 30, 2026
Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the...
Moderate
Unreviewed
CVE-2026-70442
was published
Aug 5, 2026
A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the...
Moderate
Unreviewed
CVE-2026-18818
was published
Aug 5, 2026
@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the...
Moderate
Unreviewed
CVE-2026-67332
was published
Aug 1, 2026
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
Moderate
Unreviewed
CVE-2026-66488
was published
Jul 29, 2026
A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when...
Moderate
Unreviewed
CVE-2026-18207
was published
Jul 29, 2026
An authorization issue was addressed with improved state management. This issue is fixed in...
Moderate
Unreviewed
CVE-2026-43792
was published
Jul 27, 2026
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel
Moderate
CVE-2026-49446
was published
for
github.com/azukaar/cosmos-server
(Go)
Jul 28, 2026
ProTip!
Advisories are also available from the
GraphQL API