GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
9,360 advisories
Filter by severity
The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which...
Moderate
Unreviewed
CVE-2026-82195
was published
Sep 24, 2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user...
Moderate
Unreviewed
CVE-2026-88846
was published
Sep 24, 2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any...
Moderate
Unreviewed
CVE-2026-88845
was published
Sep 24, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3...
High
Unreviewed
CVE-2026-92470
was published
Sep 24, 2026
A vulnerability was detected in ByteDance Coze Scraper Extension up to 2.0.2. Affected by this...
Low
Unreviewed
CVE-2026-96680
was published
Sep 24, 2026
A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function...
Moderate
Unreviewed
CVE-2026-96603
was published
Sep 24, 2026
A flaw was found in the Ansible Automation Platform automation-controller. When a...
Critical
Unreviewed
CVE-2026-84719
was published
Sep 23, 2026
Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.
High
Unreviewed
CVE-2026-95604
was published
Sep 23, 2026
Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.
Moderate
Unreviewed
CVE-2026-95527
was published
Sep 23, 2026
Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by...
High
Unreviewed
CVE-2026-95513
was published
Sep 23, 2026
Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.
Moderate
Unreviewed
CVE-2026-94679
was published
Sep 23, 2026
Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.
Moderate
Unreviewed
CVE-2026-94498
was published
Sep 23, 2026
Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.
Moderate
Unreviewed
CVE-2026-94080
was published
Sep 23, 2026
Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions.
Moderate
Unreviewed
CVE-2026-94079
was published
Sep 23, 2026
Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions.
Moderate
Unreviewed
CVE-2026-93620
was published
Sep 23, 2026
Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions.
Moderate
Unreviewed
CVE-2026-93529
was published
Sep 23, 2026
CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes =
(IsAuthenticated,), so DRF's...
High
Unreviewed
CVE-2026-76648
was published
Sep 23, 2026
JobJobEventsChildrenSummary view has no model/parent_model.
ModelAccessPermission...
Moderate
Unreviewed
CVE-2026-71459
was published
Sep 23, 2026
/api/v2/config/ is protected only by IsAuthenticated.
license_info (account_number,...
Moderate
Unreviewed
CVE-2026-71460
was published
Sep 23, 2026
Formie: Missing authorization on sent notification resend modal exposes submission PII
High
CVE-2026-76089
was published
for
verbb/formie
(Composer)
Sep 23, 2026
Formie: Unauthenticated users can overwrite incomplete submissions via submit action
High
CVE-2026-76087
was published
for
verbb/formie
(Composer)
Sep 23, 2026
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials
High
CVE-2026-76086
was published
for
verbb/formie
(Composer)
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to...
Moderate
Unreviewed
CVE-2026-18179
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to...
High
Unreviewed
CVE-2026-18177
was published
Sep 23, 2026
A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue...
Moderate
Unreviewed
CVE-2026-96446
was published
Sep 23, 2026
ProTip!
Advisories are also available from the
GraphQL API