GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,174 advisories
Filter by severity
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold...
High
Unreviewed
CVE-2026-76352
was published
Aug 20, 2026
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
High
GHSA-p77j-g7h5-r2vw
was published
for
geolens
(pip)
Aug 19, 2026
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
Moderate
CVE-2026-55236
was published
for
langgraph-api
(pip)
Aug 19, 2026
stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on...
Critical
Unreviewed
CVE-2026-76243
was published
Aug 19, 2026
The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-11729
was published
Aug 19, 2026
This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0...
High
Unreviewed
CVE-2026-21584
was published
Aug 19, 2026
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web...
Moderate
Unreviewed
CVE-2026-70923
was published
Aug 18, 2026
A flaw was found in the group policy provider of Keycloak authorization services, which is used...
Moderate
Unreviewed
CVE-2026-19608
was published
Aug 18, 2026
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
Critical
GHSA-m5w8-4gq2-6f8x
was published
for
vm2
(npm)
Aug 17, 2026
A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown...
Low
Unreviewed
CVE-2026-19994
was published
Aug 17, 2026
A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some...
Low
Unreviewed
CVE-2026-19997
was published
Aug 17, 2026
A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300,...
Moderate
Unreviewed
CVE-2026-19979
was published
Aug 17, 2026
A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue...
Low
Unreviewed
CVE-2026-19966
was published
Aug 17, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass...
High
Unreviewed
CVE-2026-16879
was published
Aug 14, 2026
A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability...
Low
Unreviewed
CVE-2026-19838
was published
Aug 14, 2026
A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of...
Low
Unreviewed
CVE-2026-19834
was published
Aug 14, 2026
A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some...
Low
Unreviewed
CVE-2026-19836
was published
Aug 14, 2026
A flaw has been found in francoisjacquet RosarioSIS up to 12.8. This affects the function...
Low
Unreviewed
CVE-2026-19784
was published
Aug 14, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege...
High
Unreviewed
CVE-2026-18509
was published
Aug 13, 2026
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-3835
was published
Aug 13, 2026
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation...
High
Unreviewed
CVE-2026-10543
was published
Aug 12, 2026
Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements...
High
Unreviewed
CVE-2026-72786
was published
Aug 12, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security...
Moderate
Unreviewed
CVE-2026-18144
was published
Aug 12, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege...
High
Unreviewed
CVE-2026-18499
was published
Aug 12, 2026
Winter: Authenticated backend users can bypass Users controller permission checks
High
CVE-2026-35445
was published
for
winter/wn-backend-module
(Composer)
Aug 12, 2026
ProTip!
Advisories are also available from the
GraphQL API