GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
9,356 advisories
Filter by severity
Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc...
Unknown
Unreviewed
CVE-2026-91085
was published
Sep 29, 2026
The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command...
Unknown
Unreviewed
CVE-2026-91048
was published
Sep 29, 2026
Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role...
Unknown
Unreviewed
CVE-2026-92142
was published
Sep 29, 2026
A security flaw has been discovered in REBUILD up to 4.4.11. This vulnerability affects unknown...
Moderate
Unreviewed
CVE-2026-102249
was published
Sep 29, 2026
mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController...
High
Unreviewed
CVE-2026-102365
was published
Sep 29, 2026
A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of...
Low
Unreviewed
CVE-2026-101139
was published
Sep 28, 2026
The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of...
Moderate
Unreviewed
CVE-2026-89300
was published
Sep 28, 2026
WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability ...
High
Unreviewed
CVE-2026-96538
was published
Sep 28, 2026
Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or...
Critical
Unreviewed
CVE-2026-82377
was published
Sep 28, 2026
A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function...
Critical
Unreviewed
CVE-2026-101000
was published
Sep 28, 2026
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform...
Moderate
Unreviewed
CVE-2026-97227
was published
Sep 27, 2026
The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not...
High
Unreviewed
CVE-2026-96896
was published
Sep 27, 2026
The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on...
Moderate
Unreviewed
CVE-2026-96897
was published
Sep 27, 2026
Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1...
Moderate
Unreviewed
CVE-2026-101063
was published
Sep 27, 2026
A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. This affects the...
Low
Unreviewed
CVE-2026-100879
was published
Sep 27, 2026
Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application...
Moderate
Unreviewed
CVE-2026-101047
was published
Sep 27, 2026
A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown...
Moderate
Unreviewed
CVE-2026-100744
was published
Sep 27, 2026
In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level...
High
Unreviewed
CVE-2026-100853
was published
Sep 27, 2026
AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station...
High
Unreviewed
CVE-2026-100855
was published
Sep 27, 2026
AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the Liquidsoap API endpoint...
Moderate
Unreviewed
CVE-2026-100854
was published
Sep 27, 2026
The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership...
High
Unreviewed
CVE-2026-96532
was published
Sep 26, 2026
The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or...
Low
Unreviewed
CVE-2026-96525
was published
Sep 26, 2026
Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via...
Moderate
Unreviewed
CVE-2026-78582
was published
Sep 26, 2026
SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send...
Moderate
Unreviewed
CVE-2026-100634
was published
Sep 26, 2026
ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the...
High
Unreviewed
CVE-2026-100602
was published
Sep 26, 2026
ProTip!
Advisories are also available from the
GraphQL API