GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,638
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
466 advisories
Filter by severity
Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in...
Critical
Unreviewed
CVE-2026-78069
was published
Sep 3, 2026
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs
Critical
CVE-2026-73843
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and...
Critical
Unreviewed
CVE-2026-18431
was published
Aug 26, 2026
senaite.core Vulnerable to Eval Injection and Missing Authorization
Critical
CVE-2026-54569
was published
for
senaite.core
(pip)
Aug 26, 2026
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system
Critical
CVE-2026-54523
was published
for
github.com/kyverno/kyverno
(Go)
Aug 26, 2026
Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image...
Critical
Unreviewed
CVE-2026-16645
was published
Aug 26, 2026
Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote...
Critical
Unreviewed
CVE-2026-79058
was published
Aug 25, 2026
RansomLook contains an authorization weakness in the web-based configuration editor exposed...
Critical
Unreviewed
CVE-2026-78387
was published
Aug 24, 2026
RansomLook contains an authorization flaw in its legacy database export functionality that can...
Critical
Unreviewed
CVE-2026-78370
was published
Aug 24, 2026
RansomLook does not consistently
enforce authorization checks when accessing groups, markets,...
Critical
Unreviewed
CVE-2026-78372
was published
Aug 24, 2026
Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's...
Critical
Unreviewed
CVE-2026-75866
was published
Aug 22, 2026
A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application...
Critical
Unreviewed
CVE-2026-12710
was published
Aug 22, 2026
Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom...
Critical
Unreviewed
CVE-2026-75932
was published
Aug 21, 2026
Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing...
Critical
Unreviewed
CVE-2026-77087
was published
Aug 21, 2026
The customer update route in EverShop is declared with "access": "public" in packages/evershop...
Critical
Unreviewed
CVE-2026-72843
was published
Aug 21, 2026
The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed...
Critical
Unreviewed
CVE-2026-75832
was published
Aug 18, 2026
Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization...
Critical
Unreviewed
CVE-2026-75835
was published
Aug 18, 2026
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data...
Critical
Unreviewed
CVE-2026-18316
was published
Aug 16, 2026
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass...
Critical
Unreviewed
CVE-2026-72824
was published
Aug 14, 2026
SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket...
Critical
Unreviewed
CVE-2026-72810
was published
Aug 14, 2026
SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or...
Critical
Unreviewed
CVE-2026-73608
was published
Aug 13, 2026
SiYuan versions before v3.7.4 fail to properly filter related-database content in...
Critical
Unreviewed
CVE-2026-72798
was published
Aug 12, 2026
SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating...
Critical
Unreviewed
CVE-2026-72789
was published
Aug 12, 2026
SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the...
Critical
Unreviewed
CVE-2026-72795
was published
Aug 12, 2026
ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any...
Critical
Unreviewed
CVE-2026-19656
was published
Aug 12, 2026
ProTip!
Advisories are also available from the
GraphQL API