GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,450
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,134
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
5,404 advisories
Filter by severity
In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows...
Moderate
Unreviewed
CVE-2026-12702
was published
Jul 24, 2026
The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before...
Moderate
Unreviewed
CVE-2026-12688
was published
Jul 24, 2026
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute...
High
Unreviewed
CVE-2026-35425
was published
Jul 24, 2026
Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension...
High
Unreviewed
CVE-2026-65759
was published
Jul 23, 2026
The editor popup could expose restricted module data to authenticated users without the required...
High
Unreviewed
CVE-2026-65757
was published
Jul 23, 2026
Database-update requests lacked consistent token and Super User checks, this could cause...
High
Unreviewed
CVE-2026-64876
was published
Jul 23, 2026
Administrator URL purges did not consistently require a valid token and cache-management permission.
Moderate
Unreviewed
CVE-2026-64871
was published
Jul 23, 2026
A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an...
High
Unreviewed
CVE-2024-58330
was published
Jul 23, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
Low
GHSA-whvh-wf3x-g77j
was published
for
jupyterlab
(pip)
Jul 22, 2026
Netty: Security Control Bypass via CORS Short-Circuit Failure
Moderate
CVE-2026-56746
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
Conditions administration did not consistently enforce tokens and component/mapped-item permissions.
High
Unreviewed
CVE-2026-63280
was published
Jul 22, 2026
Administrator actions, editor popups and import/export requests lacked consistent token, item...
High
Unreviewed
CVE-2026-63684
was published
Jul 22, 2026
Administrator routes and replacement requests did not consistently require Super User permission...
High
Unreviewed
CVE-2026-63685
was published
Jul 22, 2026
User tags, filters and conditions allowed access to insufficiently restricted user fields....
Moderate
Unreviewed
CVE-2026-64794
was published
Jul 22, 2026
Content tags could use ignore flags or property overrides to render restricted or unpublished...
Critical
Unreviewed
CVE-2026-64793
was published
Jul 22, 2026
Administrator routes and install/update/uninstall processing did not consistently enforce...
High
Unreviewed
CVE-2026-64791
was published
Jul 22, 2026
Free did not require both the article creator and last modifier to be Super Users before...
Critical
Unreviewed
CVE-2026-64796
was published
Jul 22, 2026
Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching...
High
Unreviewed
CVE-2026-63265
was published
Jul 22, 2026
The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor...
High
Unreviewed
CVE-2026-63047
was published
Jul 22, 2026
The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new...
Moderate
Unreviewed
CVE-2026-14322
was published
Jul 22, 2026
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal...
Moderate
Unreviewed
CVE-2026-62562
was published
Jul 22, 2026
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...
High
Unreviewed
CVE-2026-62574
was published
Jul 22, 2026
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll -...
High
Unreviewed
CVE-2026-62521
was published
Jul 22, 2026
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll)....
Critical
Unreviewed
CVE-2026-62549
was published
Jul 22, 2026
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll)....
High
Unreviewed
CVE-2026-62557
was published
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API