GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
2,666 advisories
Filter by severity
When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly...
High
Unreviewed
CVE-2026-18664
was published
Sep 1, 2026
A vulnerability exists in the affected products that allows a threat actor to create a project...
High
Unreviewed
CVE-2024-7953
was published
Sep 1, 2026
Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows...
High
Unreviewed
CVE-2026-51766
was published
Sep 1, 2026
Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155.
High
Unreviewed
CVE-2026-84128
was published
Sep 1, 2026
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.
High
Unreviewed
CVE-2026-84117
was published
Sep 1, 2026
AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows...
High
Unreviewed
CVE-2026-84187
was published
Sep 1, 2026
A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems,...
High
Unreviewed
CVE-2026-84165
was published
Sep 1, 2026
Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows...
High
Unreviewed
CVE-2026-51735
was published
Aug 31, 2026
Incorrect access control in the delPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015...
High
Unreviewed
CVE-2026-51716
was published
Aug 31, 2026
Incorrect access control in the delUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015...
High
Unreviewed
CVE-2026-51719
was published
Aug 31, 2026
Incorrect access control in the setDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows...
High
Unreviewed
CVE-2026-51695
was published
Aug 31, 2026
Incorrect access control in the setStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015...
High
Unreviewed
CVE-2026-51694
was published
Aug 31, 2026
Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via...
High
Unreviewed
CVE-2026-78074
was published
Aug 31, 2026
Incorrect access control in the getCloudDownloadStatus function of TOTOLINK T6 4.1.5cu...
High
Unreviewed
CVE-2026-51671
was published
Aug 31, 2026
Incorrect access control in the setLanguageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015...
High
Unreviewed
CVE-2026-51668
was published
Aug 31, 2026
Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows...
High
Unreviewed
CVE-2026-51673
was published
Aug 31, 2026
@hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows...
High
Unreviewed
CVE-2026-82861
was published
Aug 31, 2026
WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log...
High
Unreviewed
CVE-2026-40463
was published
Aug 31, 2026
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does...
High
Unreviewed
CVE-2026-76586
was published
Aug 29, 2026
Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu...
High
Unreviewed
CVE-2026-51662
was published
Aug 29, 2026
Incorrect access control in the getDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows...
High
Unreviewed
CVE-2026-51658
was published
Aug 28, 2026
Incorrect access control in the getUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015...
High
Unreviewed
CVE-2026-51659
was published
Aug 28, 2026
Incorrect access control in the getMeshRoutingTable function of TOTOLINK T6 4.1.5cu.748_B20211015...
High
Unreviewed
CVE-2026-51642
was published
Aug 28, 2026
Incorrect access control in the getWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015...
High
Unreviewed
CVE-2026-51641
was published
Aug 28, 2026
Incorrect access control in the getCrpcConfig function of TOTOLINK T6 4.1.5cu.748_B20211015...
High
Unreviewed
CVE-2026-51644
was published
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API