GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
116 advisories
Filter by severity
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate...
Critical
Unreviewed
CVE-2026-59118
was published
Aug 7, 2026
A privilege escalation vulnerability allows local users to execute arbitrary code as root via...
Critical
Unreviewed
CVE-2026-18367
was published
Aug 7, 2026
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
Critical
GHSA-p279-2cqp-84jg
was published
for
org.openidentityplatform.opendj:opendj-server-legacy
(Maven)
Jul 24, 2026
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information...
Critical
Unreviewed
CVE-2026-62835
was published
Jul 24, 2026
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate...
Critical
Unreviewed
CVE-2026-56160
was published
Jul 24, 2026
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
Critical
GHSA-8fpg-xm3f-6cx3
was published
for
next-auth
(npm)
Jul 23, 2026
SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group...
Critical
Unreviewed
CVE-2026-28312
was published
Jul 21, 2026
IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected...
Critical
Unreviewed
CVE-2026-7663
was published
Jun 30, 2026
Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise
Critical
CVE-2026-55166
was published
for
lemur
(pip)
Jun 25, 2026
OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints
Critical
CVE-2026-45052
was published
for
org.openidentityplatform.openam:openam-federation-library
(Maven)
Jun 24, 2026
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass...
Critical
Unreviewed
CVE-2026-10580
was published
Jun 5, 2026
Shopper: Authorization bypass and RBAC privilege escalation in team settings
Critical
CVE-2026-47744
was published
for
shopper/framework
(Composer)
Jun 5, 2026
Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose...
Critical
Unreviewed
CVE-2026-48579
was published
Jun 5, 2026
In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a...
Critical
Unreviewed
CVE-2026-0072
was published
Jun 1, 2026
stigmem-node: Auth-disabled deployments may grant broad anonymous access outside loopback
Critical
GHSA-fp6w-8wpg-74g5
was published
for
stigmem-node
(pip)
May 29, 2026
Apache Tomcat - Security constraints not correctly applied
Critical
CVE-2026-43515
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
May 12, 2026
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information...
Critical
Unreviewed
CVE-2026-33823
was published
May 8, 2026
The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP...
Critical
Unreviewed
CVE-2026-30496
was published
May 7, 2026
Paperclip: Cross-tenant agent API token minting via missing assertCompanyAccess on /api/agents/:id/keys
Critical
GHSA-47wq-cj9q-wpmp
was published
for
@paperclipai/server
(npm)
Apr 16, 2026
Juju: CloudSpec method leaking cloud credentials
Critical
CVE-2026-5412
was published
for
github.com/juju/juju
(Go)
Apr 10, 2026
Signal K Server: Privilege Escalation by Admin Role Injection via /enableSecurity
Critical
CVE-2026-33950
was published
for
signalk-server
(npm)
Apr 3, 2026
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges...
Critical
Unreviewed
CVE-2026-32213
was published
Apr 3, 2026
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to...
Critical
Unreviewed
CVE-2026-33105
was published
Apr 3, 2026
gRPC-Go has an authorization bypass via missing leading slash in :path
Critical
CVE-2026-33186
was published
for
google.golang.org/grpc
(Go)
Mar 18, 2026
The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication...
Critical
Unreviewed
CVE-2026-30702
was published
Mar 18, 2026
ProTip!
Advisories are also available from the
GraphQL API