GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
4,490 advisories
Filter by severity
The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in...
Critical
Unreviewed
CVE-2026-14526
was published
Aug 8, 2026
Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on...
High
Unreviewed
CVE-2024-8424
was published
Nov 8, 2024
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's...
High
Unreviewed
CVE-2026-15215
was published
Aug 7, 2026
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated...
Critical
Unreviewed
CVE-2026-64637
was published
Aug 7, 2026
A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user...
Moderate
Unreviewed
CVE-2026-16071
was published
Aug 5, 2026
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used...
Critical
Unreviewed
CVE-2026-1728
was published
Aug 6, 2026
Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate...
Moderate
Unreviewed
CVE-2026-70443
was published
Aug 5, 2026
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an...
Moderate
Unreviewed
CVE-2026-20308
was published
Aug 5, 2026
An improper privilege management vulnerability in the REST API document patch operation of...
Critical
Unreviewed
CVE-2026-8709
was published
Aug 5, 2026
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query...
Critical
Unreviewed
CVE-2026-7329
was published
Aug 5, 2026
An improper privilege management vulnerability in the REST API document processing pipeline of...
High
Unreviewed
CVE-2026-7327
was published
Aug 5, 2026
An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic...
Critical
Unreviewed
CVE-2026-9193
was published
Aug 5, 2026
The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce...
Critical
Unreviewed
CVE-2026-16256
was published
Aug 2, 2026
The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic...
High
Unreviewed
CVE-2026-15368
was published
Aug 1, 2026
The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all...
High
Unreviewed
CVE-2026-18322
was published
Aug 5, 2026
A vulnerability allowing local privilege escalation to the Reporter service context.
High
Unreviewed
CVE-2026-64634
was published
Aug 4, 2026
Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Install /...
Moderate
Unreviewed
CVE-2026-61064
was published
Jul 22, 2026
The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based...
High
Unreviewed
CVE-2026-18759
was published
Aug 4, 2026
Improper access control in the IRP_MJ_WRITE command interface in
Wellbia XIGNCODE3 xhunter2.sys,...
Moderate
Unreviewed
CVE-2026-15430
was published
Aug 3, 2026
The Import and export users and customers WordPress plugin before 2.4.2 does not enforce...
Critical
Unreviewed
CVE-2026-16534
was published
Aug 3, 2026
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component:...
High
Unreviewed
CVE-2026-60625
was published
Jul 22, 2026
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with...
High
Unreviewed
CVE-2026-67356
was published
Aug 2, 2026
The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to...
High
Unreviewed
CVE-2026-16635
was published
Aug 1, 2026
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in...
High
Unreviewed
CVE-2026-15414
was published
Aug 1, 2026
The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level...
High
Unreviewed
CVE-2026-12251
was published
Jul 31, 2026
ProTip!
Advisories are also available from the
GraphQL API