GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,535
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,515
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
259 advisories
Filter by severity
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the...
Critical
Unreviewed
CVE-2026-18963
was published
Aug 18, 2026
Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link...
Critical
Unreviewed
CVE-2026-15689
was published
Aug 15, 2026
The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient...
Critical
Unreviewed
CVE-2026-12949
was published
Aug 14, 2026
Budibase versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api...
High
Unreviewed
CVE-2026-72856
was published
Aug 14, 2026
Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
Critical
Unreviewed
CVE-2026-66691
was published
Aug 13, 2026
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
Critical
Unreviewed
CVE-2026-61967
was published
Aug 13, 2026
n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange...
High
Unreviewed
CVE-2026-72772
was published
Aug 11, 2026
A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the...
Low
Unreviewed
CVE-2026-19361
was published
Aug 9, 2026
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to...
Critical
Unreviewed
CVE-2026-14364
was published
Aug 7, 2026
The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is...
Critical
Unreviewed
CVE-2026-9273
was published
Aug 5, 2026
A logic vulnerability in the password reset token validation routine implemented by osTicket in...
Critical
Unreviewed
CVE-2026-18363
was published
Jul 30, 2026
Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service...
Moderate
Unreviewed
CVE-2026-64635
was published
Jul 30, 2026
Capgo before 12.128.2 allows email address changes without requiring current password re...
High
Unreviewed
CVE-2026-56308
was published
Jul 12, 2026
A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function...
Moderate
Unreviewed
CVE-2026-15479
was published
Jul 12, 2026
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress...
High
Unreviewed
CVE-2026-15155
was published
Jul 11, 2026
The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in...
High
Unreviewed
CVE-2026-7655
was published
Jul 11, 2026
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS...
High
Unreviewed
CVE-2026-13020
was published
Jul 7, 2026
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing...
Critical
Unreviewed
CVE-2026-13019
was published
Jul 7, 2026
Kimai Password Reset Link Remains Valid After Password Change
Low
GHSA-m492-gv72-xvxj
was published
for
kimai/kimai
(Composer)
Jul 1, 2026
An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2026-37106
was published
Jul 1, 2026
The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset...
Critical
Unreviewed
CVE-2026-12416
was published
Jun 24, 2026
The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password...
Critical
Unreviewed
CVE-2026-12417
was published
Jun 24, 2026
Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and...
Critical
Unreviewed
CVE-2026-56081
was published
Jun 20, 2026
The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all...
Critical
Unreviewed
CVE-2026-11551
was published
Jun 20, 2026
A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the...
Moderate
Unreviewed
CVE-2026-12066
was published
Jun 12, 2026
ProTip!
Advisories are also available from the
GraphQL API