GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,958 advisories
Filter by severity
The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting...
Moderate
Unreviewed
CVE-2026-18934
was published
Aug 10, 2026
A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission...
Moderate
Unreviewed
CVE-2026-19550
was published
Aug 11, 2026
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role...
Moderate
Unreviewed
CVE-2026-18698
was published
Aug 11, 2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a...
Moderate
Unreviewed
CVE-2026-48411
was published
Aug 11, 2026
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform...
Moderate
Unreviewed
CVE-2026-63512
was published
Aug 11, 2026
Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an...
Moderate
Unreviewed
CVE-2026-62775
was published
Aug 11, 2026
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an...
Moderate
Unreviewed
CVE-2026-48375
was published
Aug 11, 2026
Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows...
Moderate
Unreviewed
CVE-2026-18348
was published
Aug 11, 2026
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
Moderate
CVE-2026-71433
was published
for
langgraph-checkpoint-postgres
(pip)
Aug 6, 2026
Windows Hello Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2021-34466
was published
May 24, 2022
A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an...
Moderate
Unreviewed
CVE-2026-37171
was published
Aug 7, 2026
Apache Polaris did not consistently validate storage locations supplied during table and view...
Moderate
Unreviewed
CVE-2026-64640
was published
Aug 6, 2026
Improper Authorization vulnerability in Apache Answer.
This issue affects Apache Answer: through...
Moderate
Unreviewed
CVE-2026-50749
was published
Aug 5, 2026
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
Moderate
CVE-2026-54765
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
Moderate
CVE-2026-71325
was published
for
github.com/traefik/traefik
(Go)
Aug 6, 2026
Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server...
Moderate
Unreviewed
CVE-2026-18954
was published
Aug 5, 2026
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
Moderate
CVE-2026-65602
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 5, 2026
Duplicate Advisory: Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
Moderate
GHSA-7m3p-wc52-rmc6
was published
for
github.com/traefik/traefik
(Go)
Jul 22, 2026
•
withdrawn
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
Moderate
CVE-2026-65601
was published
for
Traefik
(Go)
Aug 5, 2026
Duplicate Advisory: Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
Moderate
GHSA-6mxq-jr92-3h2r
was published
for
github.com/traefik/traefik
(Go)
Jul 22, 2026
•
withdrawn
In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can...
Moderate
Unreviewed
CVE-2026-71201
was published
Aug 5, 2026
Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient...
Moderate
Unreviewed
CVE-2026-71247
was published
Aug 5, 2026
In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control...
Moderate
Unreviewed
CVE-2026-71192
was published
Aug 5, 2026
In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-*...
Moderate
Unreviewed
CVE-2026-71191
was published
Aug 5, 2026
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
Moderate
CVE-2026-70490
was published
for
open-webui
(pip)
Aug 4, 2026
ProTip!
Advisories are also available from the
GraphQL API