GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,936 advisories
Filter by severity
Incorrect authorization in Downloads in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-78898
was published
Aug 25, 2026
PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability...
Moderate
Unreviewed
CVE-2026-62382
was published
Aug 22, 2026
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-79088
was published
Aug 25, 2026
DataEase before 2.10.26 contains multiple access control defects in the sharing link module....
Moderate
Unreviewed
CVE-2026-82879
was published
Aug 31, 2026
ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller...
Moderate
Unreviewed
CVE-2026-82875
was published
Aug 31, 2026
GROWI contains an incorrect authorization vulnerability. If this vulnerability is exploited, an...
Moderate
Unreviewed
CVE-2026-68951
was published
Aug 31, 2026
The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an...
Moderate
Unreviewed
CVE-2026-77786
was published
Aug 29, 2026
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
Moderate
CVE-2026-55873
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 28, 2026
Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-79211
was published
Aug 25, 2026
Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65...
Moderate
Unreviewed
CVE-2026-79213
was published
Aug 25, 2026
Incorrect authorization in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a...
Moderate
Unreviewed
CVE-2026-79217
was published
Aug 25, 2026
Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-79077
was published
Aug 25, 2026
Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2026-62904
was published
Aug 28, 2026
Incorrect authorization in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-79258
was published
Aug 25, 2026
Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-79199
was published
Aug 25, 2026
Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-79050
was published
Aug 25, 2026
Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-79003
was published
Aug 25, 2026
Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-79137
was published
Aug 25, 2026
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-79143
was published
Aug 25, 2026
Incorrect access control in the AdHoc User creation form of EMSigner v2.8.7 allows...
Moderate
Unreviewed
CVE-2023-43901
was published
Nov 14, 2023
Snipe-IT has incorrect permission for legacy license checkin API
Moderate
CVE-2026-55479
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Snipe-IT's import created_by can be overwritten
Moderate
CVE-2026-55475
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
Moderate
CVE-2026-55472
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Snipe-IT has an authorization bypass on print inventory page
Moderate
CVE-2026-55462
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project
Moderate
CVE-2026-54766
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API