GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
409 advisories
Filter by severity
PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
High
CVE-2026-57121
was published
for
praisonai-platform
(pip)
Jun 18, 2026
Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
High
CVE-2026-54012
was published
for
open-webui
(pip)
Jun 17, 2026
DevGuard has improper authorization on public assets
High
CVE-2026-48089
was published
for
github.com/l3montree-dev/devguard
(Go)
Jun 11, 2026
Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
Moderate
CVE-2026-49397
was published
for
github.com/nezhahq/nezha
(Go)
Jun 10, 2026
Dex: Token-exchange endpoint is missing AllowedConnectors enforcement
High
GHSA-7qjx-gp9h-65qj
was published
for
github.com/dexidp/dex
(Go)
Jun 9, 2026
nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator
High
CVE-2026-47726
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 8, 2026
Weaviate has an Improper Authorization issue
Low
CVE-2026-11500
was published
for
github.com/weaviate/weaviate
(Go)
Jun 8, 2026
Shopper: Authorization bypass and RBAC privilege escalation in team settings
Critical
CVE-2026-47744
was published
for
shopper/framework
(Composer)
Jun 5, 2026
Hono: JWT middleware accepts any Authorization scheme, not only Bearer
Moderate
CVE-2026-47673
was published
for
hono
(npm)
Jun 4, 2026
Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
High
CVE-2026-45337
was published
for
better-auth
(npm)
Jun 4, 2026
Apache ActiveMQ server has an incomplete authorization workflow
Moderate
CVE-2026-46605
was published
for
org.apache.activemq:apache-activemq
(Maven)
Jun 1, 2026
Apache Airflow has an Improper Authorization issue
Low
CVE-2026-40963
was published
for
apache-airflow
(pip)
Jun 1, 2026
AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
Low
CVE-2026-10212
was published
for
AstrBot
(pip)
Jun 1, 2026
stigmem-node: Auth-disabled deployments may grant broad anonymous access outside loopback
Critical
GHSA-fp6w-8wpg-74g5
was published
for
stigmem-node
(pip)
May 29, 2026
NocoDB: Shared-base link access can invite arbitrary users as persistent base members
Moderate
CVE-2026-46552
was published
for
nocodb
(npm)
May 21, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse
Low
CVE-2026-46668
was published
for
github.com/authzed/spicedb
(Go)
May 21, 2026
shopper/framework: Authorization bypass in multiple Livewire admin components
High
CVE-2026-47740
was published
for
shopper/framework
(Composer)
May 18, 2026
eduMFA: Incorrect InnoDB snapshot isolation possibly allows token reusage
High
GHSA-qq2p-4282-cfc5
was published
for
edumfa
(pip)
May 18, 2026
AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an unauthenticated user enumeration sibling that survives `d9cdc7024`
Moderate
CVE-2026-45620
was published
for
WWBN/AVideo
(Composer)
May 18, 2026
Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]
Moderate
CVE-2026-45365
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI missing authorization check at the model update function - models from other users can be updated
Moderate
CVE-2026-45345
was published
for
open-webui
(pip)
May 14, 2026
SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs
High
CVE-2026-45371
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
May 13, 2026
SiYuan: Broken access control in `/api/tag/getTag` — Reader role can mutate `Conf.Tag.Sort` and persist to disk
Moderate
CVE-2026-45147
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
May 13, 2026
Apache Tomcat - Security constraints not correctly applied
Critical
CVE-2026-43515
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
May 12, 2026
ExternalSecrets vulnerable to privilege escalation with secret overwriting
Moderate
CVE-2026-42876
was published
for
github.com/external-secrets/external-secrets/apis
(Go)
May 8, 2026
ProTip!
Advisories are also available from the
GraphQL API