GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,936 advisories
Filter by severity
Copyparty vulnerable to file/dirkey confusion
Moderate
CVE-2026-70657
was published
for
copyparty
(pip)
Aug 18, 2026
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce...
Moderate
Unreviewed
CVE-2026-9859
was published
Aug 18, 2026
This vulnerability only affects Grafana stacks configured with multiple organizations; single...
Moderate
Unreviewed
CVE-2026-11817
was published
Aug 18, 2026
The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the...
Moderate
Unreviewed
CVE-2026-19726
was published
Aug 16, 2026
OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By...
Moderate
Unreviewed
CVE-2026-74248
was published
Aug 14, 2026
Adobe Genuine Software Integrity Service was affected by an Incorrect Authorization vulnerability...
Moderate
Unreviewed
CVE-2026-71381
was published
Aug 7, 2026
Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict...
Moderate
Unreviewed
CVE-2026-16048
was published
Aug 17, 2026
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile...
Moderate
Unreviewed
CVE-2026-10527
was published
Aug 17, 2026
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on...
Moderate
Unreviewed
CVE-2026-16046
was published
Aug 17, 2026
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth...
Moderate
Unreviewed
CVE-2026-16045
was published
Aug 17, 2026
Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign...
Moderate
Unreviewed
CVE-2026-15754
was published
Aug 17, 2026
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from...
Moderate
Unreviewed
CVE-2026-16044
was published
Aug 17, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
Moderate
GHSA-8rw6-p7m8-63jp
was published
for
surrealdb
(Rust)
Aug 14, 2026
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the...
Moderate
Unreviewed
CVE-2026-73049
was published
Aug 14, 2026
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics...
Moderate
Unreviewed
CVE-2026-72673
was published
Aug 13, 2026
SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS...
Moderate
Unreviewed
CVE-2025-71390
was published
Jul 18, 2026
An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows...
Moderate
Unreviewed
CVE-2026-19182
was published
Aug 13, 2026
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout...
Moderate
Unreviewed
CVE-2026-72788
was published
Aug 12, 2026
SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag...
Moderate
Unreviewed
CVE-2026-72792
was published
Aug 12, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19...
Moderate
Unreviewed
CVE-2026-18433
was published
Aug 12, 2026
The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended...
Moderate
Unreviewed
CVE-2026-15388
was published
Aug 12, 2026
The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended...
Moderate
Unreviewed
CVE-2026-18046
was published
Aug 12, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19...
Moderate
Unreviewed
CVE-2026-8667
was published
Aug 12, 2026
The Pinpoint Booking System WordPress plugin through 2.9.9.6.9 does not validate the booking...
Moderate
Unreviewed
CVE-2026-15229
was published
Aug 10, 2026
A bundle writer may create misleading release promotion information under specific conditions.
Moderate
Unreviewed
CVE-2026-68755
was published
Aug 12, 2026
ProTip!
Advisories are also available from the
GraphQL API