GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,450
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,134
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
5,404 advisories
Filter by severity
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache...
High
Unreviewed
CVE-2026-41920
was published
Jul 29, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
Critical
CVE-2026-64863
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM...
Moderate
Unreviewed
CVE-2026-7362
was published
Jul 28, 2026
[This CNA information record relates to multiple CVEs; the
text explains which aspects...
High
Unreviewed
CVE-2026-62427
was published
Jul 28, 2026
The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a...
Moderate
Unreviewed
CVE-2026-14926
was published
Jul 28, 2026
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer...
Critical
Unreviewed
CVE-2021-32084
was published
Jul 28, 2026
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8,...
Moderate
Unreviewed
CVE-2026-64723
was published
Jul 27, 2026
This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and...
Moderate
Unreviewed
CVE-2026-64732
was published
Jul 27, 2026
An authorization issue was addressed with improved state management. This issue is fixed in macOS...
High
Unreviewed
CVE-2026-64737
was published
Jul 27, 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Critical
Unreviewed
CVE-2026-64738
was published
Jul 27, 2026
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS...
Critical
Unreviewed
CVE-2026-64702
was published
Jul 27, 2026
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2026-43819
was published
Jul 27, 2026
An access issue was addressed with improved access restrictions. This issue is fixed in Safari 26...
Moderate
Unreviewed
CVE-2026-43821
was published
Jul 27, 2026
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7...
Critical
Unreviewed
CVE-2026-43779
was published
Jul 27, 2026
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2026-43763
was published
Jul 27, 2026
An access issue was addressed with improved access restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2026-43760
was published
Jul 27, 2026
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in...
High
Unreviewed
CVE-2026-28945
was published
Jul 27, 2026
An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60...
High
Unreviewed
CVE-2026-12990
was published
Jul 27, 2026
The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to...
High
Unreviewed
CVE-2026-14235
was published
Jul 27, 2026
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
High
GHSA-rm67-g9ch-vxff
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Improper access control in Azure App Service allows an unauthorized attacker to elevate...
Critical
Unreviewed
CVE-2026-58630
was published
Jul 24, 2026
Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue...
High
Unreviewed
CVE-2026-9765
was published
Jul 24, 2026
ImageMagick: Policy Bypass in script operation due to missing checks
Low
GHSA-vghg-5jrg-2398
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass possible with matrix-backed operations
Low
GHSA-rvhp-75f6-9jqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper...
High
Unreviewed
CVE-2026-14603
was published
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API