GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
8,734 advisories
Filter by severity
Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints,...
High
Unreviewed
CVE-2026-82245
was published
Aug 28, 2026
Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources...
High
Unreviewed
CVE-2026-82239
was published
Aug 28, 2026
Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user...
High
Unreviewed
CVE-2026-82240
was published
Aug 28, 2026
The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person...
Moderate
Unreviewed
CVE-2026-77701
was published
Aug 28, 2026
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70...
Moderate
Unreviewed
CVE-2026-12514
was published
Aug 28, 2026
The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any...
High
Unreviewed
CVE-2026-75339
was published
Aug 28, 2026
Certain configuration endpoints may lack proper server-side
authorization checks, allowing...
High
Unreviewed
CVE-2026-75813
was published
Aug 28, 2026
PayRange API is missing proper authorization on management endpoints, which allows verbose...
High
Unreviewed
CVE-2026-18965
was published
Aug 28, 2026
LimeSurvey Community Edition 7.0.5 contains an authenticated improper authorization vulnerability...
Moderate
Unreviewed
CVE-2026-65931
was published
Aug 27, 2026
Affected versions of Flowintel expose the /my_assignment/user API endpoint to any authenticated...
Moderate
Unreviewed
CVE-2026-81819
was published
Aug 27, 2026
Baserow dispatches an Application Builder data source without acting on the result of its...
High
Unreviewed
CVE-2026-81335
was published
Aug 27, 2026
Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.
Moderate
Unreviewed
CVE-2026-81272
was published
Aug 27, 2026
Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.
Moderate
Unreviewed
CVE-2026-81276
was published
Aug 27, 2026
Subscriber Broken Access Control in Ditty <= 3.1.67 versions.
Moderate
Unreviewed
CVE-2026-81274
was published
Aug 27, 2026
Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.
Moderate
Unreviewed
CVE-2026-81279
was published
Aug 27, 2026
Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
High
Unreviewed
CVE-2026-80433
was published
Aug 27, 2026
Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.
High
Unreviewed
CVE-2026-27330
was published
Aug 27, 2026
The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price...
High
Unreviewed
CVE-2026-78137
was published
Aug 27, 2026
The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX...
Moderate
Unreviewed
CVE-2026-13414
was published
Aug 27, 2026
one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits...
High
Unreviewed
CVE-2026-81027
was published
Aug 26, 2026
Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc...
High
Unreviewed
CVE-2026-81035
was published
Aug 26, 2026
The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and...
Critical
Unreviewed
CVE-2026-18431
was published
Aug 26, 2026
TarsWeb enforces its per-application roles by calling AuthService from individual controller...
High
Unreviewed
CVE-2026-80348
was published
Aug 26, 2026
The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its...
High
Unreviewed
CVE-2026-74928
was published
Aug 26, 2026
The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest...
Moderate
Unreviewed
CVE-2026-77694
was published
Aug 26, 2026
ProTip!
Advisories are also available from the
GraphQL API