GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
5,446 advisories
Filter by severity
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS...
Critical
Unreviewed
CVE-2026-64702
was published
Jul 27, 2026
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2026-43819
was published
Jul 27, 2026
An access issue was addressed with improved access restrictions. This issue is fixed in Safari 26...
Moderate
Unreviewed
CVE-2026-43821
was published
Jul 27, 2026
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7...
Critical
Unreviewed
CVE-2026-43779
was published
Jul 27, 2026
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2026-43763
was published
Jul 27, 2026
An access issue was addressed with improved access restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2026-43760
was published
Jul 27, 2026
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in...
High
Unreviewed
CVE-2026-28945
was published
Jul 27, 2026
An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60...
High
Unreviewed
CVE-2026-12990
was published
Jul 27, 2026
The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to...
High
Unreviewed
CVE-2026-14235
was published
Jul 27, 2026
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
High
GHSA-rm67-g9ch-vxff
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Improper access control in Azure App Service allows an unauthorized attacker to elevate...
Critical
Unreviewed
CVE-2026-58630
was published
Jul 24, 2026
Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue...
High
Unreviewed
CVE-2026-9765
was published
Jul 24, 2026
ImageMagick: Policy Bypass in script operation due to missing checks
Low
GHSA-vghg-5jrg-2398
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass possible with matrix-backed operations
Low
GHSA-rvhp-75f6-9jqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper...
High
Unreviewed
CVE-2026-14603
was published
Jul 24, 2026
In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows...
Moderate
Unreviewed
CVE-2026-12702
was published
Jul 24, 2026
The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before...
Moderate
Unreviewed
CVE-2026-12688
was published
Jul 24, 2026
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute...
High
Unreviewed
CVE-2026-35425
was published
Jul 24, 2026
Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension...
High
Unreviewed
CVE-2026-65759
was published
Jul 23, 2026
The editor popup could expose restricted module data to authenticated users without the required...
High
Unreviewed
CVE-2026-65757
was published
Jul 23, 2026
Administrator URL purges did not consistently require a valid token and cache-management permission.
Moderate
Unreviewed
CVE-2026-64871
was published
Jul 23, 2026
Database-update requests lacked consistent token and Super User checks, this could cause...
High
Unreviewed
CVE-2026-64876
was published
Jul 23, 2026
A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an...
High
Unreviewed
CVE-2024-58330
was published
Jul 23, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
Low
GHSA-whvh-wf3x-g77j
was published
for
jupyterlab
(pip)
Jul 22, 2026
Netty: Security Control Bypass via CORS Short-Circuit Failure
Moderate
CVE-2026-56746
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API