GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,820 advisories
Filter by severity
Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the...
Moderate
Unreviewed
CVE-2026-69094
was published
Aug 3, 2026
Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile...
Critical
Unreviewed
CVE-2026-2346
was published
Aug 3, 2026
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9...
Moderate
Unreviewed
CVE-2026-16564
was published
Aug 3, 2026
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9...
Moderate
Unreviewed
CVE-2026-16565
was published
Aug 3, 2026
The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check...
Moderate
Unreviewed
CVE-2026-15260
was published
Aug 3, 2026
Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA)...
Critical
Unreviewed
CVE-2026-68582
was published
Aug 2, 2026
better-auth passkey versions before 1.4.0 contain an insecure direct object reference...
High
Unreviewed
CVE-2025-71400
was published
Aug 2, 2026
ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers...
Critical
Unreviewed
CVE-2026-67342
was published
Aug 1, 2026
better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM...
High
Unreviewed
CVE-2026-67331
was published
Aug 1, 2026
@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10,...
High
Unreviewed
CVE-2026-67329
was published
Aug 1, 2026
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information...
Moderate
Unreviewed
CVE-2025-14073
was published
Aug 1, 2026
Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII
Moderate
CVE-2026-68501
was published
for
sylius/mollie-plugin
(Composer)
Jul 31, 2026
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook
High
CVE-2026-68500
was published
for
sylius/mollie-plugin
(Composer)
Jul 31, 2026
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
Moderate
Unreviewed
CVE-2026-17567
was published
Jul 31, 2026
The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its...
Moderate
Unreviewed
CVE-2026-8155
was published
Jul 31, 2026
The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or...
Moderate
Unreviewed
CVE-2026-14847
was published
Jul 31, 2026
The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is...
Moderate
Unreviewed
CVE-2026-14843
was published
Jul 31, 2026
The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any...
Low
Unreviewed
CVE-2026-14927
was published
Jul 31, 2026
The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the...
Moderate
Unreviewed
CVE-2026-15209
was published
Jul 31, 2026
The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records...
Moderate
Unreviewed
CVE-2026-12376
was published
Jul 31, 2026
The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation...
Moderate
Unreviewed
CVE-2026-12697
was published
Jul 31, 2026
IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in...
Moderate
Unreviewed
CVE-2026-10700
was published
Jul 30, 2026
IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other...
High
Unreviewed
CVE-2026-12945
was published
Jul 30, 2026
A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer...
High
Unreviewed
CVE-2026-15658
was published
Jul 30, 2026
Julep contains an insecure direct object reference vulnerability in the get_execution_details...
High
Unreviewed
CVE-2026-67348
was published
Jul 30, 2026
ProTip!
Advisories are also available from the
GraphQL API