GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
405 advisories
Filter by severity
Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII
Moderate
CVE-2026-68501
was published
for
sylius/mollie-plugin
(Composer)
Jul 31, 2026
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook
High
CVE-2026-68500
was published
for
sylius/mollie-plugin
(Composer)
Jul 31, 2026
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
Low
CVE-2026-52841
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
Moderate
CVE-2026-52837
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
Low
CVE-2026-52839
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
Moderate
GHSA-86cx-wwf4-phq4
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
Moderate
GHSA-p6ph-3jx2-3337
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
High
GHSA-rm67-g9ch-vxff
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
Critical
GHSA-p279-2cqp-84jg
was published
for
org.openidentityplatform.opendj:opendj-server-legacy
(Maven)
Jul 24, 2026
Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
High
GHSA-c8vc-7pv3-g98p
was published
for
@budibase/server
(npm)
Jul 24, 2026
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
Low
CVE-2026-59215
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
High
CVE-2026-59216
was published
for
open-webui
(pip)
Jul 24, 2026
@better-auth/stripe: cross-organization billing tampering in organization subscription actions
High
GHSA-h3rm-78g3-j7cp
was published
for
@better-auth/stripe
(npm)
Jul 24, 2026
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
Critical
GHSA-rjg6-39jm-rgg4
was published
for
@better-auth/scim
(npm)
Jul 24, 2026
n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
Moderate
CVE-2026-59253
was published
for
n8n
(npm)
Jul 22, 2026
n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
Moderate
CVE-2026-59254
was published
for
n8n
(npm)
Jul 22, 2026
n8n: External Secrets Permission Bypass via Expression Parser Mismatch
Moderate
CVE-2026-59259
was published
for
n8n
(npm)
Jul 22, 2026
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
High
CVE-2026-65016
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
High
GHSA-mwq7-vcmc-cm4q
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
Gitea LFS Deploy-Key Privilege Escalation
Moderate
CVE-2026-58435
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
Low
CVE-2026-58445
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
High
CVE-2026-28740
was published
for
gitea.dev
(Go)
Jul 21, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
Moderate
CVE-2026-57886
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: draft release attachment disclosure via missing web authorization
Moderate
CVE-2026-58432
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Directus: Authorization-dependent response served from unsegmented cache key
High
CVE-2026-61836
was published
for
directus
(npm)
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API