GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
9,360 advisories
Filter by severity
TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints...
Moderate
Unreviewed
CVE-2026-100303
was published
Sep 25, 2026
TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated...
Moderate
Unreviewed
CVE-2026-100305
was published
Sep 25, 2026
Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47...
Moderate
Unreviewed
CVE-2026-80432
was published
Sep 25, 2026
Bludit CMS through 3.22.0 contains a missing authorization vulnerability that allows...
High
Unreviewed
CVE-2026-93365
was published
Sep 25, 2026
Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0...
Moderate
Unreviewed
CVE-2026-95835
was published
Sep 25, 2026
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2026-89406
was published
Sep 25, 2026
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2026-92713
was published
Sep 25, 2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass...
Critical
Unreviewed
CVE-2026-89055
was published
Sep 25, 2026
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-92829
was published
Sep 25, 2026
The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-19775
was published
Sep 25, 2026
ServiceNow has remediated an authorization bypass security issue that was identified in the...
High
Unreviewed
CVE-2026-86857
was published
Sep 24, 2026
ServiceNow has remediated a missing authorization vulnerability that was identified in the...
Critical
Unreviewed
CVE-2026-86860
was published
Sep 24, 2026
GROWI applies its page-viewer permission check to attachment requests only when the request...
High
Unreviewed
CVE-2026-80191
was published
Sep 24, 2026
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
Moderate
CVE-2026-56742
was published
for
github.com/cilium/cilium
(Go)
Sep 24, 2026
ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass
Critical
CVE-2026-61604
was published
for
github.com/ixofoundation/ixo-blockchain
(Go)
Sep 24, 2026
A flaw in the authorization mechanism for Media Gateway API in Genetec Security Center may allow...
Moderate
Unreviewed
CVE-2026-65422
was published
Sep 24, 2026
HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability...
Critical
Unreviewed
CVE-2026-97360
was published
Sep 24, 2026
Black Candy through 3.2.1 fails to scope playlist search queries to the authenticated session...
Moderate
Unreviewed
CVE-2026-97061
was published
Sep 24, 2026
The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized...
Moderate
Unreviewed
CVE-2026-3253
was published
Sep 24, 2026
The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized...
Moderate
Unreviewed
CVE-2026-4806
was published
Sep 24, 2026
A flaw was found in the Admin REST API of Keycloak, an identity and access management solution....
Moderate
Unreviewed
CVE-2026-97311
was published
Sep 24, 2026
A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained...
Moderate
Unreviewed
CVE-2026-97177
was published
Sep 24, 2026
A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity...
Moderate
Unreviewed
CVE-2026-97176
was published
Sep 24, 2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user...
Moderate
Unreviewed
CVE-2026-88847
was published
Sep 24, 2026
The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX...
Moderate
Unreviewed
CVE-2026-80338
was published
Sep 24, 2026
ProTip!
Advisories are also available from the
GraphQL API