GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
69 advisories
Filter by severity
The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object...
Low
Unreviewed
CVE-2026-16070
was published
Aug 4, 2026
The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a...
Low
Unreviewed
CVE-2026-15231
was published
Aug 3, 2026
The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any...
Low
Unreviewed
CVE-2026-14927
was published
Jul 31, 2026
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
Low
CVE-2026-52841
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
Low
CVE-2026-52839
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
An insecure direct object reference
vulnerability in Koollab LMS allowed an authenticated user to...
Low
Unreviewed
CVE-2026-63241
was published
Jul 29, 2026
The "quick setup" view presented to users after they first create an
event allows to set up the...
Low
Unreviewed
CVE-2026-18028
was published
Jul 28, 2026
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
Low
CVE-2026-59215
was published
for
open-webui
(pip)
Jul 24, 2026
AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability...
Low
Unreviewed
CVE-2026-65699
was published
Jul 23, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
Low
CVE-2026-58445
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX...
Low
Unreviewed
CVE-2026-12906
was published
Jul 16, 2026
Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11,...
Low
Unreviewed
CVE-2026-15058
was published
Jul 14, 2026
Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture...
Low
Unreviewed
CVE-2026-61971
was published
Jul 13, 2026
LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows...
Low
Unreviewed
CVE-2026-59100
was published
Jul 2, 2026
Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation
Low
GHSA-j5mc-p8qg-39j7
was published
for
kimai/kimai
(Composer)
Jul 2, 2026
ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers
Low
CVE-2026-55670
was published
for
github.com/zitadel/zitadel
(Go)
Jun 18, 2026
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin...
Low
Unreviewed
CVE-2026-12102
was published
Jun 18, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8,...
Low
Unreviewed
CVE-2026-6976
was published
Jun 11, 2026
PhoenixStorybook has cross-session PubSub topic injection via URL parameter
Low
CVE-2026-47068
was published
for
phoenix_storybook
(Erlang)
Jun 9, 2026
Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known
Low
CVE-2026-47716
was published
for
bugsink
(pip)
Jun 5, 2026
Bugsink: Issue event views can show an event from another project if its UUID is known
Low
CVE-2026-47715
was published
for
bugsink
(pip)
Jun 5, 2026
NocoDB: Missing Ownership Check in MCP Attachment Read
Low
CVE-2026-47388
was published
for
nocodb
(npm)
Jun 5, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
Low
CVE-2026-9712
was published
for
pretix
(pip)
May 27, 2026
Authorization bypass in the entry duplication feature in Devolutions Server allows an...
Low
Unreviewed
CVE-2026-9248
was published
May 26, 2026
Concrete CMS is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog
Low
CVE-2026-8347
was published
for
concrete5/concrete5
(Composer)
May 26, 2026
ProTip!
Advisories are also available from the
GraphQL API