GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
9,356 advisories
Filter by severity
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not perform a capability check on...
Moderate
Unreviewed
CVE-2026-87981
was published
Sep 23, 2026
The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of...
Moderate
Unreviewed
CVE-2026-86842
was published
Sep 23, 2026
The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation...
Moderate
Unreviewed
CVE-2026-86785
was published
Sep 23, 2026
The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification...
Low
Unreviewed
CVE-2026-87074
was published
Sep 23, 2026
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or...
Low
Unreviewed
CVE-2026-93507
was published
Sep 23, 2026
The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the...
Moderate
Unreviewed
CVE-2026-93510
was published
Sep 23, 2026
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its...
High
Unreviewed
CVE-2026-93508
was published
Sep 23, 2026
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature...
Moderate
Unreviewed
CVE-2026-87979
was published
Sep 23, 2026
The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on...
Moderate
Unreviewed
CVE-2026-18364
was published
Sep 23, 2026
The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per...
Moderate
Unreviewed
CVE-2026-83555
was published
Sep 23, 2026
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before...
Moderate
Unreviewed
CVE-2026-84027
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated...
Moderate
Unreviewed
CVE-2026-18132
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated...
Moderate
Unreviewed
CVE-2026-18156
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated...
High
Unreviewed
CVE-2026-17618
was published
Sep 23, 2026
Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher
Low
CVE-2026-84298
was published
for
github.com/hatchet-dev/hatchet
(Go)
Sep 22, 2026
Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope
Low
CVE-2026-77637
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Sep 22, 2026
Unleash: Missing await on permission check + cross-project IDOR in admin API
High
CVE-2026-77426
was published
for
unleash-server
(npm)
Sep 22, 2026
[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token
Critical
CVE-2026-77244
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass
High
CVE-2026-77243
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards
Moderate
CVE-2026-69190
was published
for
org.graylog2:graylog2-server
(Maven)
Sep 22, 2026
deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes
High
CVE-2026-63116
was published
for
@deepstream/server
(npm)
Sep 22, 2026
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass...
High
Unreviewed
CVE-2026-43643
was published
Sep 22, 2026
MISP contains an authorization flaw in the Organisation model's captureOrg method. When the ...
Moderate
Unreviewed
CVE-2026-95697
was published
Sep 22, 2026
MISP contains an access control flaw in the EventReports functionality. The...
Moderate
Unreviewed
CVE-2026-95685
was published
Sep 22, 2026
MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in...
High
Unreviewed
CVE-2026-93344
was published
Sep 22, 2026
ProTip!
Advisories are also available from the
GraphQL API