GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
4,452 advisories
Filter by severity
The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all...
High
Unreviewed
CVE-2026-12144
was published
Jul 29, 2026
A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A...
High
Unreviewed
CVE-2026-18107
was published
Jul 28, 2026
The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions...
High
Unreviewed
CVE-2026-15992
was published
Jul 28, 2026
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption
High
CVE-2026-50570
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress...
High
Unreviewed
CVE-2026-14328
was published
Jul 28, 2026
The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting...
Critical
Unreviewed
CVE-2026-14545
was published
Jul 28, 2026
An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under...
High
Unreviewed
CVE-2026-66015
was published
Jul 27, 2026
phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController:...
High
Unreviewed
CVE-2026-66399
was published
Jul 27, 2026
The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not...
High
Unreviewed
CVE-2026-13152
was published
Jul 27, 2026
The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end...
Critical
Unreviewed
CVE-2026-12394
was published
Jul 27, 2026
Budibase: Privilege escalation via public role assignment API missing app-level authorization
High
GHSA-j9fc-w3mr-x6mv
was published
for
@budibase/server
(npm)
Jul 24, 2026
Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE,...
High
Unreviewed
CVE-2026-12502
was published
Jul 24, 2026
A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user...
Moderate
Unreviewed
CVE-2026-16743
was published
Jul 24, 2026
Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully...
High
Unreviewed
CVE-2026-7483
was published
Jul 24, 2026
Local privilege escalation potentially allowed an attacker to execute arbitrary code as a...
High
Unreviewed
CVE-2026-10610
was published
Jul 24, 2026
The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation...
High
Unreviewed
CVE-2026-12981
was published
Jul 24, 2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &...
High
Unreviewed
CVE-2026-12497
was published
Jul 24, 2026
The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and...
High
Unreviewed
CVE-2026-12736
was published
Jul 24, 2026
Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233.
This issue...
High
Unreviewed
CVE-2026-34496
was published
Jul 23, 2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate...
High
Unreviewed
CVE-2026-38764
was published
Jul 23, 2026
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or...
Critical
Unreviewed
CVE-2026-15630
was published
Jul 23, 2026
Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController...
High
Unreviewed
CVE-2026-65897
was published
Jul 23, 2026
The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all...
High
Unreviewed
CVE-2026-15017
was published
Jul 23, 2026
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware ...
High
Unreviewed
CVE-2026-60439
was published
Jul 23, 2026
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware ...
High
Unreviewed
CVE-2026-60373
was published
Jul 23, 2026
ProTip!
Advisories are also available from the
GraphQL API