GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
4,135 advisories
Filter by severity
Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote...
Unknown
Unreviewed
CVE-2026-84332
was published
Sep 2, 2026
Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote...
Unknown
Unreviewed
CVE-2026-84355
was published
Sep 2, 2026
Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote...
Unknown
Unreviewed
CVE-2026-84335
was published
Sep 2, 2026
Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote...
Unknown
Unreviewed
CVE-2026-84331
was published
Sep 2, 2026
Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed...
Unknown
Unreviewed
CVE-2026-84327
was published
Sep 2, 2026
Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75...
Unknown
Unreviewed
CVE-2026-84334
was published
Sep 2, 2026
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote...
Unknown
Unreviewed
CVE-2026-84354
was published
Sep 2, 2026
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification,...
Moderate
Unreviewed
CVE-2026-78606
was published
Sep 1, 2026
Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting...
High
Unreviewed
CVE-2026-63137
was published
Sep 1, 2026
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via...
Moderate
Unreviewed
CVE-2026-72641
was published
Sep 1, 2026
Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security...
Moderate
Unreviewed
CVE-2026-72633
was published
Sep 1, 2026
Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote...
High
Unreviewed
CVE-2026-58566
was published
Sep 1, 2026
Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with...
High
Unreviewed
CVE-2026-76111
was published
Sep 1, 2026
The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder,...
High
Unreviewed
CVE-2026-75921
was published
Sep 1, 2026
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not apply the API-key scope cap...
Critical
Unreviewed
CVE-2026-80204
was published
Aug 31, 2026
Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(),...
Critical
Unreviewed
CVE-2026-80202
was published
Aug 31, 2026
DataEase before 2.10.26 contains multiple access control defects in the sharing link module....
Moderate
Unreviewed
CVE-2026-82879
was published
Aug 31, 2026
ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller...
Moderate
Unreviewed
CVE-2026-82875
was published
Aug 31, 2026
GROWI contains an incorrect authorization vulnerability. If this vulnerability is exploited, an...
Moderate
Unreviewed
CVE-2026-68951
was published
Aug 31, 2026
Frappe Framework development builds contain an authorization flaw in the render_jinja_template...
High
Unreviewed
CVE-2026-82634
was published
Aug 30, 2026
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in...
High
Unreviewed
CVE-2026-82463
was published
Aug 29, 2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check...
Low
Unreviewed
CVE-2026-77704
was published
Aug 29, 2026
The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an...
Moderate
Unreviewed
CVE-2026-77786
was published
Aug 29, 2026
The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the...
Critical
Unreviewed
CVE-2026-80203
was published
Aug 29, 2026
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
Moderate
CVE-2026-55873
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API