GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,508 advisories
Filter by severity
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
High
CVE-2026-54563
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Aug 26, 2026
Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing....
High
Unreviewed
CVE-2026-18985
was published
Aug 26, 2026
In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application...
High
Unreviewed
CVE-2026-80182
was published
Aug 26, 2026
In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms ...
High
Unreviewed
CVE-2026-80184
was published
Aug 26, 2026
Incorrect authorization in Sandbox in Google Chrome prior to 152.0.7977.65 allowed a remote...
High
Unreviewed
CVE-2026-79218
was published
Aug 25, 2026
Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker...
High
Unreviewed
CVE-2026-78911
was published
Aug 25, 2026
Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65...
High
Unreviewed
CVE-2026-78892
was published
Aug 25, 2026
Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:read scope, a read-only scope,...
High
Unreviewed
CVE-2026-79673
was published
Aug 25, 2026
General user can mint admin access tokens via /access-tokens
This issue affects Apache...
High
Unreviewed
CVE-2026-49050
was published
Aug 25, 2026
The extension fails to require the dedicated admin confirmation token when processing an admin...
High
Unreviewed
CVE-2026-77134
was published
Aug 25, 2026
Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows...
High
Unreviewed
CVE-2026-71510
was published
Aug 24, 2026
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
High
Unreviewed
CVE-2026-71506
was published
Aug 24, 2026
Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC...
High
Unreviewed
CVE-2025-63080
was published
Aug 24, 2026
Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote...
High
Unreviewed
CVE-2026-76019
was published
Aug 20, 2026
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate
High
GHSA-fm29-4mq3-phg6
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)
High
CVE-2026-54180
was published
for
backpack/crud
(Composer)
Aug 20, 2026
A low privileged remote attacker with a valid session can submit a request to the user creation...
High
Unreviewed
CVE-2026-14949
was published
Aug 20, 2026
In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk...
High
Unreviewed
CVE-2026-76391
was published
Aug 20, 2026
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060...
High
Unreviewed
CVE-2026-17063
was published
Aug 19, 2026
Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common...
High
Unreviewed
CVE-2026-19198
was published
Aug 19, 2026
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80,...
High
Unreviewed
CVE-2026-17429
was published
Aug 19, 2026
Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode
High
CVE-2026-55643
was published
for
snipe/snipe-it
(Composer)
Aug 19, 2026
Summary
An authenticated organization user who can create or edit alert rules in a folder can...
High
Unreviewed
CVE-2026-17183
was published
Aug 19, 2026
stigmem versions before 0.9.0a12 contain a broken object level authorization vulnerability in the...
High
Unreviewed
CVE-2026-76238
was published
Aug 19, 2026
An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a...
High
Unreviewed
CVE-2026-70408
was published
Aug 19, 2026
ProTip!
Advisories are also available from the
GraphQL API