GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,124 advisories
Filter by severity
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate...
Critical
Unreviewed
CVE-2026-59118
was published
Aug 7, 2026
A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0....
Moderate
Unreviewed
CVE-2026-19064
was published
Aug 7, 2026
A vulnerability was identified in SourceCodester Online Examination & Learning Management System...
Moderate
Unreviewed
CVE-2026-19066
was published
Aug 7, 2026
A privilege escalation vulnerability allows local users to execute arbitrary code as root via...
Critical
Unreviewed
CVE-2026-18367
was published
Aug 7, 2026
Craft CMS: Arbitrary user password reset leading to administrator account takeover
High
GHSA-p8x7-9vfw-p7vc
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the...
Low
Unreviewed
CVE-2026-19006
was published
Aug 6, 2026
A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the...
Low
Unreviewed
CVE-2026-18992
was published
Aug 6, 2026
A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the...
Low
Unreviewed
CVE-2026-18997
was published
Aug 6, 2026
Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the...
Moderate
Unreviewed
CVE-2026-70442
was published
Aug 5, 2026
A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the...
Moderate
Unreviewed
CVE-2026-18818
was published
Aug 5, 2026
A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue...
Low
Unreviewed
CVE-2026-18773
was published
Aug 4, 2026
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
High
CVE-2026-70472
was published
for
flowise
(npm)
Aug 4, 2026
A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in...
Low
Unreviewed
CVE-2026-18722
was published
Aug 4, 2026
A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the...
Low
Unreviewed
CVE-2026-18631
was published
Aug 3, 2026
@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the...
Moderate
Unreviewed
CVE-2026-67332
was published
Aug 1, 2026
An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql...
Moderate
Unreviewed
CVE-2026-14538
was published
Jul 31, 2026
An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user...
Moderate
Unreviewed
CVE-2026-23981
was published
Jul 30, 2026
Calico's apiserver wraps tier-scoped resources so that every operation runs through...
Moderate
Unreviewed
CVE-2026-41187
was published
Jul 30, 2026
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
Moderate
Unreviewed
CVE-2026-66488
was published
Jul 29, 2026
A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when...
Moderate
Unreviewed
CVE-2026-18207
was published
Jul 29, 2026
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel
Moderate
CVE-2026-49446
was published
for
github.com/azukaar/cosmos-server
(Go)
Jul 28, 2026
Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache...
Moderate
Unreviewed
CVE-2026-61487
was published
Jul 28, 2026
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
High
CVE-2026-43983
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Jul 28, 2026
An authorization issue was addressed with improved state management. This issue is fixed in iOS...
Moderate
Unreviewed
CVE-2026-64743
was published
Jul 27, 2026
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and...
Moderate
Unreviewed
CVE-2026-64711
was published
Jul 27, 2026
ProTip!
Advisories are also available from the
GraphQL API