GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
206 advisories
Filter by severity
Missing authorization in Lighthouse in Google Chrome prior to 152.0.7977.65 allowed a remote...
Low
Unreviewed
CVE-2026-79053
was published
Aug 25, 2026
Missing authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote...
Low
Unreviewed
CVE-2026-78953
was published
Aug 25, 2026
Missing authorization issue for domain admins in CloudStack's host tags listing functionality.
...
Low
Unreviewed
CVE-2026-66721
was published
Aug 21, 2026
In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view...
Low
Unreviewed
CVE-2026-76368
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk...
Low
Unreviewed
CVE-2026-76348
was published
Aug 20, 2026
The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit...
Low
Unreviewed
CVE-2026-13173
was published
Aug 19, 2026
ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch...
Low
Unreviewed
CVE-2026-75850
was published
Aug 18, 2026
An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may...
Low
Unreviewed
CVE-2026-65926
was published
Aug 12, 2026
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
Low
CVE-2026-70483
was published
for
open-webui
(pip)
Aug 4, 2026
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership...
Low
Unreviewed
CVE-2026-16274
was published
Aug 3, 2026
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an...
Low
Unreviewed
CVE-2026-16276
was published
Aug 3, 2026
The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support...
Low
Unreviewed
CVE-2026-14862
was published
Jul 31, 2026
The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on...
Low
Unreviewed
CVE-2026-15054
was published
Jul 30, 2026
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
Low
CVE-2026-52839
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
Low
GHSA-pc2w-4mq8-32qw
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 29, 2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability...
Low
Unreviewed
CVE-2026-14821
was published
Jul 28, 2026
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Low
CVE-2026-59226
was published
for
open-webui
(pip)
Jul 24, 2026
ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check
Low
GHSA-v3j6-27vc-7pw2
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its...
Low
Unreviewed
CVE-2026-12690
was published
Jul 24, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation
Low
CVE-2026-58434
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
Low
CVE-2026-58438
was published
for
gitea.dev
(Go)
Jul 21, 2026
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element...
Low
Unreviewed
CVE-2026-16197
was published
Jul 19, 2026
A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is...
Low
Unreviewed
CVE-2026-16123
was published
Jul 18, 2026
A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function...
Low
Unreviewed
CVE-2026-16017
was published
Jul 17, 2026
The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its...
Low
Unreviewed
CVE-2026-12907
was published
Jul 16, 2026
ProTip!
Advisories are also available from the
GraphQL API