GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,936 advisories
Filter by severity
Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-78975
was published
Aug 25, 2026
Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a...
Moderate
Unreviewed
CVE-2026-79005
was published
Aug 25, 2026
Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-79179
was published
Aug 25, 2026
Incorrect authorization in Browser in Google Chrome on on Android prior to 152.0.7977.65 allowed...
Moderate
Unreviewed
CVE-2026-79225
was published
Aug 25, 2026
Incorrect authorization in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-79133
was published
Aug 25, 2026
Incorrect authorization in TabGroups in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-79107
was published
Aug 25, 2026
Incorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-78946
was published
Aug 25, 2026
phpMyFAQ public FAQ APIs expose inactive FAQ content
Moderate
GHSA-mf8r-wm2w-f8c5
was published
for
phpmyfaq/phpmyfaq
(Composer)
Aug 25, 2026
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
Moderate
GHSA-vx2m-jpxr-xv7w
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Aug 24, 2026
Mattermost doesn't require system-level permission when patching protected default system roles
Moderate
CVE-2026-6739
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 12, 2026
Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an...
Moderate
Unreviewed
CVE-2026-77923
was published
Aug 24, 2026
BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated...
Moderate
Unreviewed
CVE-2026-67204
was published
Aug 24, 2026
SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that...
Moderate
Unreviewed
CVE-2026-60083
was published
Aug 22, 2026
The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up...
Moderate
Unreviewed
CVE-2026-4245
was published
Aug 22, 2026
The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths...
Moderate
Unreviewed
CVE-2026-17559
was published
Aug 21, 2026
In Spring AI's tool calling support, the per-request tool list is advertised to the model as a...
Moderate
Unreviewed
CVE-2026-59318
was published
Aug 21, 2026
In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could...
Moderate
Unreviewed
CVE-2026-76370
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the ...
Moderate
Unreviewed
CVE-2026-76342
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the ...
Moderate
Unreviewed
CVE-2026-76341
was published
Aug 20, 2026
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access...
Moderate
Unreviewed
CVE-2026-21076
was published
Aug 10, 2026
Windows Hello Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2021-42288
was published
May 24, 2022
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access...
Moderate
Unreviewed
CVE-2026-21077
was published
Aug 10, 2026
Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization...
Moderate
Unreviewed
CVE-2026-67266
was published
Aug 19, 2026
Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user...
Moderate
Unreviewed
CVE-2026-19670
was published
Aug 18, 2026
Dolibarr contains an authorization bypass vulnerability in the clonetasks mass action that allows...
Moderate
Unreviewed
CVE-2026-73692
was published
Aug 18, 2026
ProTip!
Advisories are also available from the
GraphQL API