GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
8,734 advisories
Filter by severity
Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the...
Moderate
Unreviewed
CVE-2026-82633
was published
Aug 30, 2026
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
High
Unreviewed
CVE-2026-82475
was published
Aug 29, 2026
The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its...
Moderate
Unreviewed
CVE-2026-19430
was published
Aug 29, 2026
The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its...
Moderate
Unreviewed
CVE-2026-18234
was published
Aug 29, 2026
The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of...
Moderate
Unreviewed
CVE-2026-18233
was published
Aug 29, 2026
The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability...
Moderate
Unreviewed
CVE-2026-81346
was published
Aug 29, 2026
Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry...
High
Unreviewed
CVE-2026-80193
was published
Aug 29, 2026
StarRocks performs no privilege check when a legacy synchronous materialized view is dropped....
High
Unreviewed
CVE-2026-80346
was published
Aug 29, 2026
HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints,...
High
Unreviewed
CVE-2026-82279
was published
Aug 28, 2026
Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread...
High
Unreviewed
CVE-2026-82273
was published
Aug 28, 2026
Komodo through 2.3.2 discloses internal resource identifiers and writes audit entries before...
Moderate
Unreviewed
CVE-2026-82267
was published
Aug 28, 2026
SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalation vulnerability that allows...
High
Unreviewed
CVE-2026-56100
was published
Aug 28, 2026
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
High
CVE-2026-55638
was published
for
9router
(npm)
Aug 28, 2026
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
High
Unreviewed
CVE-2026-81767
was published
Aug 28, 2026
Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.
Moderate
Unreviewed
CVE-2026-81761
was published
Aug 28, 2026
Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
Moderate
Unreviewed
CVE-2026-81284
was published
Aug 28, 2026
Contributor Broken Access Control in WpEvently <= 5.5.0 versions.
Moderate
Unreviewed
CVE-2026-81759
was published
Aug 28, 2026
Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter
Moderate
CVE-2026-55476
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets
Moderate
CVE-2026-55548
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration
Moderate
CVE-2026-55547
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce
Moderate
CVE-2026-55545
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities
High
CVE-2026-55521
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0
Moderate
CVE-2026-55064
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe
Moderate
CVE-2026-54746
was published
for
github.com/hatchet-dev/hatchet
(Go)
Aug 28, 2026
Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api...
High
Unreviewed
CVE-2026-82242
was published
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API