GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
5,446 advisories
Filter by severity
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper...
High
Unreviewed
CVE-2026-59912
was published
Aug 3, 2026
HCL iControl is affected by Missing Access Control vulnerability. The application failed to...
Low
Unreviewed
CVE-2026-56608
was published
Aug 3, 2026
The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson...
Moderate
Unreviewed
CVE-2026-16563
was published
Aug 3, 2026
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a...
High
Unreviewed
CVE-2026-15151
was published
Aug 2, 2026
The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization...
High
Unreviewed
CVE-2026-15241
was published
Aug 2, 2026
The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an...
Moderate
Unreviewed
CVE-2026-14315
was published
Aug 1, 2026
The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the...
Moderate
Unreviewed
CVE-2026-12966
was published
Aug 1, 2026
The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any...
Moderate
Unreviewed
CVE-2026-13329
was published
Aug 1, 2026
An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows...
Critical
Unreviewed
CVE-2026-52134
was published
Aug 1, 2026
The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA)
in affected versions exposes...
Moderate
Unreviewed
CVE-2026-65311
was published
Jul 31, 2026
The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on...
Moderate
Unreviewed
CVE-2026-14834
was published
Jul 31, 2026
A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites)...
Low
Unreviewed
CVE-2026-58039
was published
Jul 31, 2026
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a...
Critical
Unreviewed
CVE-2026-66803
was published
Jul 30, 2026
MCP Ruby SDK: Ruby SSE Session Poisoning
High
CVE-2026-67431
was published
for
mcp
(RubyGems)
Jul 30, 2026
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree...
High
Unreviewed
CVE-2026-58043
was published
Jul 30, 2026
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the...
High
Unreviewed
CVE-2026-16527
was published
Jul 30, 2026
The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation...
Moderate
Unreviewed
CVE-2026-11782
was published
Jul 30, 2026
The Easy Appointments WordPress plugin through 3.12.26 does not perform any capability or nonce...
Low
Unreviewed
CVE-2026-14222
was published
Jul 30, 2026
The Easy Appointments WordPress plugin through 3.12.26 does not perform capability checks in...
Low
Unreviewed
CVE-2026-14221
was published
Jul 30, 2026
The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking...
Moderate
Unreviewed
CVE-2026-15250
was published
Jul 30, 2026
Inappropriate implementation in Browser in Google Chrome on Mac prior to 151.0.7922.72 allowed a...
Moderate
Unreviewed
CVE-2026-17996
was published
Jul 30, 2026
Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a...
Moderate
Unreviewed
CVE-2026-18004
was published
Jul 30, 2026
Inappropriate implementation in Media in Google Chrome on Android prior to 151.0.7922.72 allowed...
Moderate
Unreviewed
CVE-2026-17994
was published
Jul 30, 2026
Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an...
Moderate
Unreviewed
CVE-2026-17976
was published
Jul 30, 2026
Insufficient policy enforcement in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a...
Moderate
Unreviewed
CVE-2026-17986
was published
Jul 30, 2026
ProTip!
Advisories are also available from the
GraphQL API