GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
4,118 advisories
Filter by severity
DataEase before 2.10.26 contains multiple access control defects in the sharing link module....
Moderate
Unreviewed
CVE-2026-82879
was published
Aug 31, 2026
ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller...
Moderate
Unreviewed
CVE-2026-82875
was published
Aug 31, 2026
GROWI contains an incorrect authorization vulnerability. If this vulnerability is exploited, an...
Moderate
Unreviewed
CVE-2026-68951
was published
Aug 31, 2026
Frappe Framework development builds contain an authorization flaw in the render_jinja_template...
High
Unreviewed
CVE-2026-82634
was published
Aug 30, 2026
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in...
High
Unreviewed
CVE-2026-82463
was published
Aug 29, 2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check...
Low
Unreviewed
CVE-2026-77704
was published
Aug 29, 2026
The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an...
Moderate
Unreviewed
CVE-2026-77786
was published
Aug 29, 2026
The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the...
Critical
Unreviewed
CVE-2026-80203
was published
Aug 29, 2026
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
Moderate
CVE-2026-55873
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 28, 2026
Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked...
High
Unreviewed
CVE-2026-82272
was published
Aug 28, 2026
Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2026-62904
was published
Aug 28, 2026
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
High
CVE-2026-55638
was published
for
9router
(npm)
Aug 28, 2026
The source-address critical option in the Permissions returned by an authentication callback was...
High
Unreviewed
CVE-2026-56854
was published
Aug 28, 2026
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
High
CVE-2026-55485
was published
for
piccolo-admin
(pip)
Aug 28, 2026
Snipe-IT has incorrect permission for legacy license checkin API
Moderate
CVE-2026-55479
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Snipe-IT's import created_by can be overwritten
Moderate
CVE-2026-55475
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
Moderate
CVE-2026-55472
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Snipe-IT has an authorization bypass on print inventory page
Moderate
CVE-2026-55462
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Snipe-IT has an authorization bypass on bulk editing users
High
CVE-2026-55460
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project
Moderate
CVE-2026-54766
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when...
Critical
Unreviewed
CVE-2026-18918
was published
Aug 28, 2026
Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission....
High
Unreviewed
CVE-2026-81729
was published
Aug 27, 2026
The updateWorkspace handler in mods/identity/src/workspaces/createUpdateWorkspace.ts in Fonoster...
Moderate
Unreviewed
CVE-2026-80209
was published
Aug 27, 2026
The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation...
Moderate
Unreviewed
CVE-2026-19454
was published
Aug 27, 2026
A WebFlux application using functional endpoints and deployed with DispatcherServlet may be...
Critical
Unreviewed
CVE-2026-47892
was published
Aug 27, 2026
ProTip!
Advisories are also available from the
GraphQL API