GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
4,135 advisories
Filter by severity
Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked...
High
Unreviewed
CVE-2026-82272
was published
Aug 28, 2026
Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2026-62904
was published
Aug 28, 2026
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
High
CVE-2026-55638
was published
for
9router
(npm)
Aug 28, 2026
The source-address critical option in the Permissions returned by an authentication callback was...
High
Unreviewed
CVE-2026-56854
was published
Aug 28, 2026
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
High
CVE-2026-55485
was published
for
piccolo-admin
(pip)
Aug 28, 2026
Snipe-IT has incorrect permission for legacy license checkin API
Moderate
CVE-2026-55479
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Snipe-IT's import created_by can be overwritten
Moderate
CVE-2026-55475
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
Moderate
CVE-2026-55472
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Snipe-IT has an authorization bypass on print inventory page
Moderate
CVE-2026-55462
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Snipe-IT has an authorization bypass on bulk editing users
High
CVE-2026-55460
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project
Moderate
CVE-2026-54766
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when...
Critical
Unreviewed
CVE-2026-18918
was published
Aug 28, 2026
Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission....
High
Unreviewed
CVE-2026-81729
was published
Aug 27, 2026
The updateWorkspace handler in mods/identity/src/workspaces/createUpdateWorkspace.ts in Fonoster...
Moderate
Unreviewed
CVE-2026-80209
was published
Aug 27, 2026
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers...
Critical
Unreviewed
CVE-2026-59270
was published
Aug 27, 2026
The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation...
Moderate
Unreviewed
CVE-2026-19454
was published
Aug 27, 2026
A WebFlux application using functional endpoints and deployed with DispatcherServlet may be...
Critical
Unreviewed
CVE-2026-47892
was published
Aug 27, 2026
Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization...
High
Unreviewed
CVE-2026-43621
was published
Aug 27, 2026
On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user...
High
Unreviewed
CVE-2026-79619
was published
Aug 26, 2026
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
High
CVE-2026-54563
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Aug 26, 2026
Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing....
High
Unreviewed
CVE-2026-18985
was published
Aug 26, 2026
Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue...
Critical
Unreviewed
CVE-2026-16644
was published
Aug 26, 2026
In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application...
High
Unreviewed
CVE-2026-80182
was published
Aug 26, 2026
In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms ...
High
Unreviewed
CVE-2026-80184
was published
Aug 26, 2026
Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the...
Critical
Unreviewed
CVE-2026-68525
was published
Aug 26, 2026
ProTip!
Advisories are also available from the
GraphQL API