GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
117
GitHub Actions
55
Go
4,836
Maven
5,000+
npm
5,000+
NuGet
1,126
pip
5,000+
Pub
13
RubyGems
1,157
Rust
1,577
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
7,109 advisories
Filter by severity
Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record...
High
Unreviewed
CVE-2026-90904
was published
Sep 23, 2026
Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update...
High
Unreviewed
CVE-2026-90905
was published
Sep 23, 2026
Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow...
High
Unreviewed
CVE-2026-82368
was published
Sep 23, 2026
A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some...
Moderate
Unreviewed
CVE-2026-96513
was published
Sep 23, 2026
The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its...
Low
Unreviewed
CVE-2026-91077
was published
Sep 23, 2026
The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount...
Moderate
Unreviewed
CVE-2026-77765
was published
Sep 23, 2026
A security flaw has been discovered in theRealSain Pixtream up to...
Low
Unreviewed
CVE-2026-95830
was published
Sep 23, 2026
A vulnerability was found in anirbandutta9 College-Notes-Gallery up to...
Low
Unreviewed
CVE-2026-95820
was published
Sep 23, 2026
A vulnerability exists in the internal administrative component of Analytics and Location Engine ...
Critical
Unreviewed
CVE-2026-76709
was published
Sep 22, 2026
Nuclei: Local File Read via Workflow File-Protocol Gate Bypass
Moderate
CVE-2026-76804
was published
for
github.com/projectdiscovery/nuclei/v3
(Go)
Sep 22, 2026
Nuclei: Local File Read via MySQL Client Sandbox Bypass
Moderate
CVE-2026-76803
was published
for
github.com/projectdiscovery/nuclei/v3
(Go)
Sep 22, 2026
The Tauri updater plugin's 'check' IPC command accepts an allowDowngrades boolean parameter...
Moderate
Unreviewed
CVE-2026-95624
was published
Sep 22, 2026
A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0....
Moderate
Unreviewed
CVE-2026-95500
was published
Sep 22, 2026
A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue...
Moderate
Unreviewed
CVE-2026-95499
was published
Sep 22, 2026
An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can...
High
Unreviewed
CVE-2026-79316
was published
Sep 21, 2026
File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files...
Moderate
Unreviewed
CVE-2026-77165
was published
Sep 21, 2026
When a user creates or edits a report inside an event, MISP can identify an existing report using...
Moderate
Unreviewed
CVE-2026-94393
was published
Sep 21, 2026
The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not...
High
Unreviewed
CVE-2026-87839
was published
Sep 20, 2026
The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on...
Moderate
Unreviewed
CVE-2026-87840
was published
Sep 20, 2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a...
Moderate
Unreviewed
CVE-2026-11549
was published
Sep 18, 2026
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
High
CVE-2026-58197
was published
for
github.com/stacklok/toolhive
(Go)
Sep 18, 2026
vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an...
Moderate
Unreviewed
CVE-2026-93604
was published
Sep 18, 2026
HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which...
Moderate
Unreviewed
CVE-2026-21848
was published
Sep 18, 2026
The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled...
Moderate
Unreviewed
CVE-2026-90976
was published
Sep 18, 2026
The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to...
Moderate
Unreviewed
CVE-2026-87965
was published
Sep 18, 2026
ProTip!
Advisories are also available from the
GraphQL API