GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
203 advisories
Filter by severity
Duplicate Advisory: Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata
Moderate
GHSA-f4h3-qhg5-j6mq
was published
for
craftcms/cms
(Composer)
Jun 21, 2026
•
withdrawn
Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries
Moderate
CVE-2026-64662
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
Moderate
CVE-2026-59817
was published
for
ghost
(npm)
Aug 4, 2026
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
Moderate
CVE-2026-70488
was published
for
open-webui
(pip)
Aug 4, 2026
Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
Moderate
GHSA-2364-jh4q-m9vm
was published
for
flowise
(npm)
Aug 4, 2026
Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII
Moderate
CVE-2026-68501
was published
for
sylius/mollie-plugin
(Composer)
Jul 31, 2026
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
Moderate
CVE-2026-52837
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
Moderate
GHSA-86cx-wwf4-phq4
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
Moderate
GHSA-p6ph-3jx2-3337
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
Moderate
CVE-2026-59253
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
Moderate
GHSA-gqcv-rfj6-r29g
was published
for
n8n
(npm)
Jul 8, 2026
•
withdrawn
n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
Moderate
CVE-2026-59254
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
Moderate
GHSA-3j7v-fhjg-6rh2
was published
for
n8n
(npm)
Jul 15, 2026
•
withdrawn
n8n: External Secrets Permission Bypass via Expression Parser Mismatch
Moderate
CVE-2026-59259
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: External Secrets Permission Bypass via Expression Parser Mismatch
Moderate
GHSA-q6mx-qvhp-fqmg
was published
for
n8n
(npm)
Jul 15, 2026
•
withdrawn
Gitea LFS Deploy-Key Privilege Escalation
Moderate
CVE-2026-58435
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
Moderate
CVE-2026-57886
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: draft release attachment disclosure via missing web authorization
Moderate
CVE-2026-58432
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
NocoDB: Hidden Column Exposure in Public Shared View Endpoints
Moderate
CVE-2026-47378
was published
for
nocodb
(npm)
Jun 5, 2026
Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
Moderate
CVE-2026-54324
was published
for
github.com/daytonaio/daytona
(Go)
Jun 17, 2026
Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
Moderate
CVE-2026-54016
was published
for
open-webui
(pip)
Jun 17, 2026
Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
Moderate
CVE-2026-54015
was published
for
open-webui
(pip)
Jun 17, 2026
Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
Moderate
CVE-2026-54009
was published
for
open-webui
(pip)
Jun 17, 2026
Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar
Moderate
CVE-2026-54006
was published
for
open-webui
(pip)
Jun 17, 2026
Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center
Moderate
CVE-2025-32781
was published
for
com.ctrip.framework.apollo:apollo
(Maven)
Jul 13, 2026
ProTip!
Advisories are also available from the
GraphQL API