GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
4,022 advisories
Filter by severity
PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability...
Moderate
Unreviewed
CVE-2026-62382
was published
Aug 22, 2026
SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that...
Moderate
Unreviewed
CVE-2026-60083
was published
Aug 22, 2026
The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up...
Moderate
Unreviewed
CVE-2026-4245
was published
Aug 22, 2026
In Spring AI's tool calling support, the per-request tool list is advertised to the model as a...
Moderate
Unreviewed
CVE-2026-59318
was published
Aug 21, 2026
The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths...
Moderate
Unreviewed
CVE-2026-17559
was published
Aug 21, 2026
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0...
Low
Unreviewed
CVE-2026-16577
was published
Aug 21, 2026
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a...
Critical
Unreviewed
CVE-2026-69555
was published
Aug 21, 2026
Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote...
High
Unreviewed
CVE-2026-76019
was published
Aug 20, 2026
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate
High
GHSA-fm29-4mq3-phg6
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)
High
CVE-2026-54180
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and...
Low
Unreviewed
CVE-2026-7485
was published
Aug 20, 2026
A low privileged remote attacker with a valid session can submit a request to the user creation...
High
Unreviewed
CVE-2026-14949
was published
Aug 20, 2026
The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some...
Low
Unreviewed
CVE-2026-19699
was published
Aug 20, 2026
In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk...
High
Unreviewed
CVE-2026-76391
was published
Aug 20, 2026
In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could...
Moderate
Unreviewed
CVE-2026-76370
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the ...
Moderate
Unreviewed
CVE-2026-76342
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the ...
Moderate
Unreviewed
CVE-2026-76341
was published
Aug 20, 2026
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060...
High
Unreviewed
CVE-2026-17063
was published
Aug 19, 2026
Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common...
High
Unreviewed
CVE-2026-19198
was published
Aug 19, 2026
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80,...
High
Unreviewed
CVE-2026-17429
was published
Aug 19, 2026
Summary
An authenticated organization user who can create or edit alert rules in a folder can...
High
Unreviewed
CVE-2026-17183
was published
Aug 19, 2026
Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization...
Moderate
Unreviewed
CVE-2026-67266
was published
Aug 19, 2026
stigmem versions before 0.9.0a12 contain a broken object level authorization vulnerability in the...
High
Unreviewed
CVE-2026-76238
was published
Aug 19, 2026
The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that...
Unknown
Unreviewed
CVE-2026-49431
was published
Aug 19, 2026
An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a...
High
Unreviewed
CVE-2026-70408
was published
Aug 19, 2026
ProTip!
Advisories are also available from the
GraphQL API