GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
8,733 advisories
Filter by severity
FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController...
High
Unreviewed
CVE-2026-84715
was published
Sep 2, 2026
Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote...
Unknown
Unreviewed
CVE-2026-84328
was published
Sep 2, 2026
Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote...
Unknown
Unreviewed
CVE-2026-84323
was published
Sep 2, 2026
A flaw was found in Ansible Automation Platform's automation-controller (AWX).
The Bulk Job...
Moderate
Unreviewed
CVE-2026-84470
was published
Sep 1, 2026
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting...
Moderate
Unreviewed
CVE-2026-78603
was published
Sep 1, 2026
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse ...
Moderate
Unreviewed
CVE-2026-78608
was published
Sep 1, 2026
Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized...
Moderate
Unreviewed
CVE-2026-78597
was published
Sep 1, 2026
Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to...
Moderate
Unreviewed
CVE-2026-78607
was published
Sep 1, 2026
GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that...
High
Unreviewed
CVE-2026-84204
was published
Sep 1, 2026
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks &...
Moderate
Unreviewed
CVE-2026-19948
was published
Sep 1, 2026
Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token...
High
Unreviewed
CVE-2026-82882
was published
Sep 1, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
CVE-2026-71415
was published
for
getkirby/cms
(Composer)
Aug 31, 2026
Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
High
Unreviewed
CVE-2026-81296
was published
Aug 31, 2026
Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.
Moderate
Unreviewed
CVE-2026-81758
was published
Aug 31, 2026
Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions.
Moderate
Unreviewed
CVE-2026-81762
was published
Aug 31, 2026
Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2026-81278
was published
Aug 31, 2026
A user with organization administrator permissions can delete dashboard snapshots belonging to...
Moderate
Unreviewed
CVE-2026-19197
was published
Aug 31, 2026
The affected Ebyte
product does not provide separation between limited and administrative ...
High
Unreviewed
CVE-2026-77966
was published
Aug 31, 2026
Missing Authorization vulnerability in TBC Technology Inc. KitLogistic allows Accessing...
High
Unreviewed
CVE-2026-19616
was published
Aug 31, 2026
Missing Authorization vulnerability in John James Jacoby bbPress allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2026-74010
was published
Aug 31, 2026
DataEase versions before 2.10.26 omit object-level authorization checks on geographic information...
Moderate
Unreviewed
CVE-2026-82878
was published
Aug 31, 2026
ToolJet before v3.16.208 fails to validate organization membership in database read routes,...
High
Unreviewed
CVE-2026-82871
was published
Aug 31, 2026
Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during...
Moderate
Unreviewed
CVE-2026-82660
was published
Aug 31, 2026
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a...
Moderate
Unreviewed
CVE-2026-77013
was published
Aug 31, 2026
Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the...
Moderate
Unreviewed
CVE-2026-82633
was published
Aug 30, 2026
ProTip!
Advisories are also available from the
GraphQL API