GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
33,303 advisories
Filter by severity
The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable...
Critical
Unreviewed
CVE-2024-13784
was published
Aug 16, 2026
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data...
Critical
Unreviewed
CVE-2026-18316
was published
Aug 16, 2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in...
Critical
Unreviewed
CVE-2026-18432
was published
Aug 16, 2026
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all...
Critical
Unreviewed
CVE-2026-16098
was published
Aug 16, 2026
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to...
Critical
Unreviewed
CVE-2026-14524
was published
Aug 16, 2026
Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When...
Critical
Unreviewed
CVE-2026-74764
was published
Aug 16, 2026
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates...
Critical
Unreviewed
CVE-2026-73052
was published
Aug 16, 2026
Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in...
Critical
Unreviewed
CVE-2026-73055
was published
Aug 16, 2026
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select...
Critical
Unreviewed
CVE-2026-73050
was published
Aug 16, 2026
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji...
Critical
Unreviewed
CVE-2026-73053
was published
Aug 16, 2026
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth()...
Critical
Unreviewed
CVE-2026-73046
was published
Aug 16, 2026
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing...
Critical
Unreviewed
CVE-2026-73044
was published
Aug 16, 2026
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation,...
Critical
Unreviewed
CVE-2026-73042
was published
Aug 16, 2026
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template...
Critical
Unreviewed
CVE-2026-73043
was published
Aug 16, 2026
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the...
Critical
Unreviewed
CVE-2026-73041
was published
Aug 16, 2026
The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to...
Critical
Unreviewed
CVE-2026-18855
was published
Aug 15, 2026
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege...
Critical
Unreviewed
CVE-2026-19598
was published
Aug 15, 2026
The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type...
Critical
Unreviewed
CVE-2026-15826
was published
Aug 15, 2026
The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and...
Critical
Unreviewed
CVE-2026-16142
was published
Aug 15, 2026
The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up...
Critical
Unreviewed
CVE-2026-15303
was published
Aug 15, 2026
The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading...
Critical
Unreviewed
CVE-2026-15341
was published
Aug 15, 2026
The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to...
Critical
Unreviewed
CVE-2026-14484
was published
Aug 15, 2026
Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows...
Critical
Unreviewed
CVE-2026-73683
was published
Aug 15, 2026
Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 -...
Critical
Unreviewed
CVE-2026-67365
was published
Aug 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL...
Critical
Unreviewed
CVE-2026-17186
was published
Aug 14, 2026
ProTip!
Advisories are also available from the
GraphQL API