GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
9,361 advisories
Filter by severity
deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes
High
CVE-2026-63116
was published
for
@deepstream/server
(npm)
Sep 22, 2026
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass...
High
Unreviewed
CVE-2026-43643
was published
Sep 22, 2026
MISP contains an authorization flaw in the Organisation model's captureOrg method. When the ...
Moderate
Unreviewed
CVE-2026-95697
was published
Sep 22, 2026
MISP contains an access control flaw in the EventReports functionality. The...
Moderate
Unreviewed
CVE-2026-95685
was published
Sep 22, 2026
MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in...
High
Unreviewed
CVE-2026-93344
was published
Sep 22, 2026
MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in...
High
Unreviewed
CVE-2026-93343
was published
Sep 22, 2026
MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in...
Moderate
Unreviewed
CVE-2026-93341
was published
Sep 22, 2026
MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in...
Moderate
Unreviewed
CVE-2026-93342
was published
Sep 22, 2026
The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to...
Moderate
Unreviewed
CVE-2026-91092
was published
Sep 22, 2026
The PixelPlay plugin for WordPress is vulnerable to unauthorized API key deletion due to missing...
Moderate
Unreviewed
CVE-2025-14486
was published
Sep 22, 2026
The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due...
Moderate
Unreviewed
CVE-2026-18345
was published
Sep 22, 2026
The RW Elephant Rental Inventory plugin for WordPress is vulnerable to Missing Authorization in...
Moderate
Unreviewed
CVE-2026-4123
was published
Sep 22, 2026
The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and...
Moderate
Unreviewed
CVE-2026-7622
was published
Sep 22, 2026
The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to...
Moderate
Unreviewed
CVE-2025-14484
was published
Sep 22, 2026
The Handily plugin for WordPress is vulnerable to unauthorized payment settings modification due...
Moderate
Unreviewed
CVE-2025-14487
was published
Sep 22, 2026
jshERP through 3.6 fails to properly validate user privileges in SystemConfigService...
High
Unreviewed
CVE-2026-94495
was published
Sep 21, 2026
jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd...
High
Unreviewed
CVE-2026-94412
was published
Sep 21, 2026
jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr...
Moderate
Unreviewed
CVE-2026-94414
was published
Sep 21, 2026
jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing...
High
Unreviewed
CVE-2026-94496
was published
Sep 21, 2026
jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD...
High
Unreviewed
CVE-2026-94501
was published
Sep 21, 2026
jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType...
High
Unreviewed
CVE-2026-94411
was published
Sep 21, 2026
When a regular user adds a reference between objects or attributes, MISP checks whether the user...
Moderate
Unreviewed
CVE-2026-94394
was published
Sep 21, 2026
The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in...
Low
Unreviewed
CVE-2026-86802
was published
Sep 21, 2026
A flaw was found in the Authorization Services component of Keycloak, an open-source identity and...
Moderate
Unreviewed
CVE-2026-94213
was published
Sep 21, 2026
A flaw was found in the authentication session management of Keycloak, an identity and access...
Low
Unreviewed
CVE-2026-94218
was published
Sep 21, 2026
ProTip!
Advisories are also available from the
GraphQL API