GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,519
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,512
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
5,534 advisories
Filter by severity
A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue...
Low
Unreviewed
CVE-2026-19839
was published
Aug 14, 2026
File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook...
High
Unreviewed
CVE-2026-72837
was published
Aug 14, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
High
CVE-2026-54526
was published
for
github.com/argoproj/argo-workflows
(Go)
Aug 13, 2026
JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in...
Low
Unreviewed
CVE-2026-73626
was published
Aug 13, 2026
IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in...
High
Unreviewed
CVE-2026-13367
was published
Aug 12, 2026
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper...
High
Unreviewed
CVE-2026-59917
was published
Aug 12, 2026
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an...
High
Unreviewed
CVE-2026-59914
was published
Aug 12, 2026
Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 -...
Moderate
Unreviewed
CVE-2026-67287
was published
Aug 12, 2026
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton...
Moderate
Unreviewed
CVE-2026-67284
was published
Aug 12, 2026
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton...
Moderate
Unreviewed
CVE-2026-67283
was published
Aug 12, 2026
The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually...
Critical
Unreviewed
CVE-2026-16538
was published
Aug 12, 2026
The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its...
High
Unreviewed
CVE-2026-13171
was published
Aug 12, 2026
The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission...
Moderate
Unreviewed
CVE-2026-14859
was published
Aug 12, 2026
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-66804
was published
Aug 11, 2026
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges...
High
Unreviewed
CVE-2026-65773
was published
Aug 11, 2026
No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized...
High
Unreviewed
CVE-2026-65675
was published
Aug 11, 2026
Improper access control for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2...
High
Unreviewed
CVE-2026-20789
was published
Aug 11, 2026
Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel...
High
Unreviewed
CVE-2026-20898
was published
Aug 11, 2026
Improper access control for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device...
High
Unreviewed
CVE-2026-20741
was published
Aug 11, 2026
Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow...
High
Unreviewed
CVE-2026-20716
was published
Aug 11, 2026
A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated...
High
Unreviewed
CVE-2026-72600
was published
Aug 11, 2026
A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author...
High
Unreviewed
CVE-2026-72596
was published
Aug 11, 2026
A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to...
High
Unreviewed
CVE-2026-72601
was published
Aug 11, 2026
ProTip!
Advisories are also available from the
GraphQL API