GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
2,012 advisories
Filter by severity
The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and...
High
Unreviewed
CVE-2026-14357
was published
Sep 2, 2026
FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController...
High
Unreviewed
CVE-2026-84715
was published
Sep 2, 2026
GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that...
High
Unreviewed
CVE-2026-84204
was published
Sep 1, 2026
Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token...
High
Unreviewed
CVE-2026-82882
was published
Sep 1, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
CVE-2026-71415
was published
for
getkirby/cms
(Composer)
Aug 31, 2026
Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
High
Unreviewed
CVE-2026-81296
was published
Aug 31, 2026
The affected Ebyte
product does not provide separation between limited and administrative ...
High
Unreviewed
CVE-2026-77966
was published
Aug 31, 2026
Missing Authorization vulnerability in TBC Technology Inc. KitLogistic allows Accessing...
High
Unreviewed
CVE-2026-19616
was published
Aug 31, 2026
ToolJet before v3.16.208 fails to validate organization membership in database read routes,...
High
Unreviewed
CVE-2026-82871
was published
Aug 31, 2026
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
High
Unreviewed
CVE-2026-82475
was published
Aug 29, 2026
Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry...
High
Unreviewed
CVE-2026-80193
was published
Aug 29, 2026
StarRocks performs no privilege check when a legacy synchronous materialized view is dropped....
High
Unreviewed
CVE-2026-80346
was published
Aug 29, 2026
HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints,...
High
Unreviewed
CVE-2026-82279
was published
Aug 28, 2026
Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread...
High
Unreviewed
CVE-2026-82273
was published
Aug 28, 2026
SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalation vulnerability that allows...
High
Unreviewed
CVE-2026-56100
was published
Aug 28, 2026
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
High
CVE-2026-55638
was published
for
9router
(npm)
Aug 28, 2026
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
High
Unreviewed
CVE-2026-81767
was published
Aug 28, 2026
Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities
High
CVE-2026-55521
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api...
High
Unreviewed
CVE-2026-82242
was published
Aug 28, 2026
Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints,...
High
Unreviewed
CVE-2026-82245
was published
Aug 28, 2026
Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources...
High
Unreviewed
CVE-2026-82239
was published
Aug 28, 2026
Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user...
High
Unreviewed
CVE-2026-82240
was published
Aug 28, 2026
The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any...
High
Unreviewed
CVE-2026-75339
was published
Aug 28, 2026
Certain configuration endpoints may lack proper server-side
authorization checks, allowing...
High
Unreviewed
CVE-2026-75813
was published
Aug 28, 2026
PayRange API is missing proper authorization on management endpoints, which allows verbose...
High
Unreviewed
CVE-2026-18965
was published
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API