GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
9,356 advisories
Filter by severity
Jenkins MCP Server Plugin missing a permission check
Moderate
CVE-2026-57300
was published
for
io.jenkins.plugins:mcp-server
(Maven)
Jun 24, 2026
Jenkins Contrast Continuous Application Security Plugin missing permission checks
Moderate
CVE-2026-57299
was published
for
org.jenkins-ci.plugins:contrast-continuous-application-security
(Maven)
Jun 24, 2026
Jenkins Gitee Plugin missing permission checks
Moderate
CVE-2026-57291
was published
for
org.jenkins-ci.plugins:gitee
(Maven)
Jun 24, 2026
Jenkins Gitee Plugin has an incorrect permission check that allows enumerating credentials IDs
Moderate
CVE-2026-57293
was published
for
org.jenkins-ci.plugins:gitee
(Maven)
Jun 24, 2026
Jenkins EC2 Fleet Plugin has a missing permission check
Moderate
CVE-2026-57294
was published
for
com.amazon.jenkins.fleet:ec2-fleet
(Maven)
Jun 24, 2026
Jenkins Contrast Continuous Application Security Plugin has a missing permission check
Moderate
CVE-2026-57297
was published
for
org.jenkins-ci.plugins:contrast-continuous-application-security
(Maven)
Jun 24, 2026
Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0...
Moderate
Unreviewed
CVE-2026-95835
was published
Sep 25, 2026
Bludit CMS through 3.22.0 contains a missing authorization vulnerability that allows...
High
Unreviewed
CVE-2026-93365
was published
Sep 25, 2026
Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47...
Moderate
Unreviewed
CVE-2026-80432
was published
Sep 25, 2026
Jenkins GitHub Branch Source Plugin has missing permission check that allows enumerating GitHub Enterprise server URLs
Moderate
CVE-2026-57285
was published
for
org.jenkins-ci.plugins:github-branch-source
(Maven)
Jun 24, 2026
Jenkins Git Parameter Plugin has a missing permission check that allows listing SCM branch and tag names
Moderate
CVE-2026-57286
was published
for
org.jenkins-ci.tools:git-parameter
(Maven)
Jun 24, 2026
ServiceNow has remediated an authorization bypass security issue that was identified in the...
High
Unreviewed
CVE-2026-86857
was published
Sep 24, 2026
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2026-89406
was published
Sep 25, 2026
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2026-92713
was published
Sep 25, 2026
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-92829
was published
Sep 25, 2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass...
Critical
Unreviewed
CVE-2026-89055
was published
Sep 25, 2026
The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-19775
was published
Sep 25, 2026
In multiple functions of RangingServiceImpl.java, there is a possible MITM due to a missing...
Low
Unreviewed
CVE-2026-28652
was published
Sep 8, 2026
In onCreate of ConfirmDeviceCredentialActivity.java, there is a possible unauthorized access to...
Low
Unreviewed
CVE-2026-28582
was published
Sep 8, 2026
ServiceNow has remediated a missing authorization vulnerability that was identified in the...
Critical
Unreviewed
CVE-2026-86860
was published
Sep 24, 2026
Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block...
Moderate
Unreviewed
CVE-2026-68535
was published
Sep 11, 2026
GROWI applies its page-viewer permission check to attachment requests only when the request...
High
Unreviewed
CVE-2026-80191
was published
Sep 24, 2026
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
Moderate
CVE-2026-56742
was published
for
github.com/cilium/cilium
(Go)
Sep 24, 2026
ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass
Critical
CVE-2026-61604
was published
for
github.com/ixofoundation/ixo-blockchain
(Go)
Sep 24, 2026
OpenShift Cluster Logging Operator missing authorization flaw
Moderate
CVE-2026-10609
was published
for
github.com/openshift/cluster-logging-operator
(Go)
Jun 23, 2026
ProTip!
Advisories are also available from the
GraphQL API