GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
140 advisories
Filter by severity
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege...
High
Unreviewed
CVE-2026-59567
was published
Aug 24, 2026
Wagtail: Improper restriction handling on Page translation API endpoint
Moderate
GHSA-jm5p-837g-rv8g
was published
for
wagtail
(pip)
Aug 20, 2026
Wagtail: Improper permission handling when copying snippets
Moderate
GHSA-x5cx-w6p2-mxf2
was published
for
wagtail
(pip)
Aug 20, 2026
Wagtail: Improper restriction handling on descendant collections in Documents and Images API
Moderate
GHSA-c2xx-cjmh-9q8f
was published
for
wagtail
(pip)
Aug 20, 2026
Wagtail: Identification of documents by SHA1 hash
Low
GHSA-92hv-j533-69wc
was published
for
wagtail
(pip)
Aug 20, 2026
Wagtail: Improper restriction handling on Pages admin API
Moderate
CVE-2026-55468
was published
for
wagtail
(pip)
Aug 20, 2026
Wagtail: Pages translations can be created without page permissions when using simple_translation
Moderate
CVE-2026-54262
was published
for
wagtail
(pip)
Aug 20, 2026
Wagtail: Improper permission handling in image preview
Moderate
CVE-2026-54261
was published
for
wagtail
(pip)
Aug 20, 2026
Wagtail: Improper restriction handling on Documents and Images chosen endpoints
Moderate
CVE-2026-54259
was published
for
wagtail
(pip)
Aug 20, 2026
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact...
Moderate
Unreviewed
CVE-2026-73239
was published
Aug 12, 2026
Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads
Moderate
CVE-2026-32639
was published
for
winter/wn-cms-module
(Composer)
Aug 12, 2026
Velociraptor allows multi-tenant deployments named "Orgs".
By default Velociraptor, uses the...
High
Unreviewed
CVE-2026-18860
was published
Aug 11, 2026
Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara...
Moderate
Unreviewed
CVE-2026-11804
was published
Jul 23, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
Moderate
CVE-2026-58416
was published
for
gitea.dev
(Go)
Jul 21, 2026
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin....
Moderate
Unreviewed
CVE-2026-62393
was published
Jul 14, 2026
Kernel software installed and running inside a Host VM may post improper commands to the GPU...
High
Unreviewed
CVE-2026-45196
was published
Jul 10, 2026
In Modem, there is a possible escalation of privilege due to a permissions bypass. This could...
Moderate
Unreviewed
CVE-2026-20463
was published
Jul 1, 2026
Kernel software installed and running inside a Host VM may post improper commands to the GPU...
High
Unreviewed
CVE-2026-45195
was published
Jun 26, 2026
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks.
...
Critical
Unreviewed
CVE-2026-41566
was published
Jun 25, 2026
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on...
High
Unreviewed
CVE-2026-40371
was published
Jun 9, 2026
When creating an export of all reusable media, the secrets of connected
gift cards were included...
Low
Unreviewed
CVE-2026-11764
was published
Jun 9, 2026
LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote...
Moderate
Unreviewed
CVE-2026-10549
was published
Jun 2, 2026
Keycloak Vulnerable to Improper Handling of Insufficient Permissions or Privilege
Moderate
CVE-2026-9792
was published
for
org.keycloak:keycloak-services
(Maven)
May 28, 2026
In the Linux kernel, the following vulnerability has been resolved:
selinux: fix overlayfs mmap(...
High
Unreviewed
CVE-2026-46054
was published
May 27, 2026
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read...
Moderate
Unreviewed
CVE-2026-2340
was published
May 27, 2026
ProTip!
Advisories are also available from the
GraphQL API