GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,508 advisories
Filter by severity
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints
High
CVE-2026-73841
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths
High
CVE-2026-72921
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Sep 2, 2026
A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group...
High
Unreviewed
CVE-2026-77125
was published
Sep 2, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
High
CVE-2026-81892
was published
for
easycorp/easyadmin-bundle
(Composer)
Sep 2, 2026
Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote...
High
Unreviewed
CVE-2026-84335
was published
Sep 2, 2026
Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75...
High
Unreviewed
CVE-2026-84334
was published
Sep 2, 2026
A privilege escalation vulnerability exists in the web-based management interface of HPE...
High
Unreviewed
CVE-2026-73723
was published
Sep 1, 2026
Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer....
High
Unreviewed
CVE-2026-73724
was published
Sep 1, 2026
A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful...
High
Unreviewed
CVE-2026-73708
was published
Sep 1, 2026
A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer....
High
Unreviewed
CVE-2026-73702
was published
Sep 1, 2026
Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer....
High
Unreviewed
CVE-2026-73707
was published
Sep 1, 2026
Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting...
High
Unreviewed
CVE-2026-63137
was published
Sep 1, 2026
Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote...
High
Unreviewed
CVE-2026-58566
was published
Sep 1, 2026
Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with...
High
Unreviewed
CVE-2026-76111
was published
Sep 1, 2026
The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder,...
High
Unreviewed
CVE-2026-75921
was published
Sep 1, 2026
Frappe Framework development builds contain an authorization flaw in the render_jinja_template...
High
Unreviewed
CVE-2026-82634
was published
Aug 30, 2026
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in...
High
Unreviewed
CVE-2026-82463
was published
Aug 29, 2026
Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked...
High
Unreviewed
CVE-2026-82272
was published
Aug 28, 2026
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
High
CVE-2026-55638
was published
for
9router
(npm)
Aug 28, 2026
The source-address critical option in the Permissions returned by an authentication callback was...
High
Unreviewed
CVE-2026-56854
was published
Aug 28, 2026
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
High
CVE-2026-55485
was published
for
piccolo-admin
(pip)
Aug 28, 2026
Snipe-IT has an authorization bypass on bulk editing users
High
CVE-2026-55460
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission....
High
Unreviewed
CVE-2026-81729
was published
Aug 27, 2026
Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization...
High
Unreviewed
CVE-2026-43621
was published
Aug 27, 2026
On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user...
High
Unreviewed
CVE-2026-79619
was published
Aug 26, 2026
ProTip!
Advisories are also available from the
GraphQL API