GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
9,360 advisories
Filter by severity
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management...
Moderate
Unreviewed
CVE-2026-94215
was published
Sep 21, 2026
Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure...
High
Unreviewed
CVE-2026-94113
was published
Sep 20, 2026
The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before...
Low
Unreviewed
CVE-2026-92965
was published
Sep 20, 2026
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management...
Moderate
Unreviewed
CVE-2026-94001
was published
Sep 19, 2026
A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and...
Moderate
Unreviewed
CVE-2026-93999
was published
Sep 19, 2026
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management...
Moderate
Unreviewed
CVE-2026-94000
was published
Sep 19, 2026
The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-9613
was published
Sep 19, 2026
The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and...
Moderate
Unreviewed
CVE-2026-18346
was published
Sep 19, 2026
The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all...
Moderate
Unreviewed
CVE-2026-9766
was published
Sep 19, 2026
The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to...
Moderate
Unreviewed
CVE-2026-9615
was published
Sep 19, 2026
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Moderate
Unreviewed
CVE-2026-9232
was published
Sep 19, 2026
The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization...
Moderate
Unreviewed
CVE-2026-9858
was published
Sep 19, 2026
The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post...
Moderate
Unreviewed
CVE-2026-1984
was published
Sep 19, 2026
The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI...
Moderate
Unreviewed
CVE-2026-15946
was published
Sep 19, 2026
The Metasync plugin for WordPress is vulnerable to unauthorized modification of data due to a...
Moderate
Unreviewed
CVE-2026-15947
was published
Sep 19, 2026
The Bread plugin for WordPress is vulnerable to information exposure in versions up to and...
Moderate
Unreviewed
CVE-2026-4792
was published
Sep 19, 2026
The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to...
Moderate
Unreviewed
CVE-2026-2278
was published
Sep 19, 2026
The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting...
Moderate
Unreviewed
CVE-2026-92435
was published
Sep 19, 2026
The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7...
Moderate
Unreviewed
CVE-2026-92430
was published
Sep 19, 2026
The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-11899
was published
Sep 19, 2026
The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of...
Critical
Unreviewed
CVE-2026-86591
was published
Sep 19, 2026
The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check...
High
Unreviewed
CVE-2026-85574
was published
Sep 19, 2026
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-88944
was published
Sep 19, 2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for...
Moderate
Unreviewed
CVE-2026-89334
was published
Sep 19, 2026
The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in...
Moderate
Unreviewed
CVE-2026-15760
was published
Sep 19, 2026
ProTip!
Advisories are also available from the
GraphQL API