GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
599 advisories
Filter by severity
Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes)...
High
Unreviewed
CVE-2026-71242
was published
Aug 5, 2026
Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce...
High
Unreviewed
CVE-2026-55739
was published
Aug 5, 2026
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
High
CVE-2026-70476
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
High
CVE-2026-69258
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration
High
CVE-2026-69250
was published
for
flowise
(npm)
Aug 4, 2026
better-auth passkey versions before 1.4.0 contain an insecure direct object reference...
High
Unreviewed
CVE-2025-71400
was published
Aug 2, 2026
better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM...
High
Unreviewed
CVE-2026-67331
was published
Aug 1, 2026
@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10,...
High
Unreviewed
CVE-2026-67329
was published
Aug 1, 2026
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook
High
CVE-2026-68500
was published
for
sylius/mollie-plugin
(Composer)
Jul 31, 2026
IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other...
High
Unreviewed
CVE-2026-12945
was published
Jul 30, 2026
A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer...
High
Unreviewed
CVE-2026-15658
was published
Jul 30, 2026
Julep contains an insecure direct object reference vulnerability in the get_execution_details...
High
Unreviewed
CVE-2026-67348
was published
Jul 30, 2026
The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and...
High
Unreviewed
CVE-2026-13178
was published
Jul 30, 2026
An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor...
High
Unreviewed
CVE-2025-60931
was published
Jul 29, 2026
SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the...
High
Unreviewed
CVE-2026-57510
was published
Jul 28, 2026
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
High
Unreviewed
CVE-2026-59546
was published
Jul 27, 2026
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
High
Unreviewed
CVE-2026-59539
was published
Jul 27, 2026
In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended...
High
Unreviewed
CVE-2026-17527
was published
Jul 27, 2026
Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated...
High
Unreviewed
CVE-2026-66412
was published
Jul 27, 2026
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
High
GHSA-rm67-g9ch-vxff
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
High
GHSA-c8vc-7pv3-g98p
was published
for
@budibase/server
(npm)
Jul 24, 2026
sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that...
High
Unreviewed
CVE-2026-65708
was published
Jul 24, 2026
sysPass through version 3.2.11 contains a missing authorization vulnerability that allows...
High
Unreviewed
CVE-2026-65710
was published
Jul 24, 2026
sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the...
High
Unreviewed
CVE-2026-65709
was published
Jul 24, 2026
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
High
CVE-2026-59216
was published
for
open-webui
(pip)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API