GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,450
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,134
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,077 advisories
Filter by severity
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache...
High
Unreviewed
CVE-2026-41920
was published
Jul 29, 2026
[This CNA information record relates to multiple CVEs; the
text explains which aspects...
High
Unreviewed
CVE-2026-62427
was published
Jul 28, 2026
An authorization issue was addressed with improved state management. This issue is fixed in macOS...
High
Unreviewed
CVE-2026-64737
was published
Jul 27, 2026
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in...
High
Unreviewed
CVE-2026-28945
was published
Jul 27, 2026
An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60...
High
Unreviewed
CVE-2026-12990
was published
Jul 27, 2026
The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to...
High
Unreviewed
CVE-2026-14235
was published
Jul 27, 2026
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
High
GHSA-rm67-g9ch-vxff
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue...
High
Unreviewed
CVE-2026-9765
was published
Jul 24, 2026
The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper...
High
Unreviewed
CVE-2026-14603
was published
Jul 24, 2026
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute...
High
Unreviewed
CVE-2026-35425
was published
Jul 24, 2026
Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension...
High
Unreviewed
CVE-2026-65759
was published
Jul 23, 2026
The editor popup could expose restricted module data to authenticated users without the required...
High
Unreviewed
CVE-2026-65757
was published
Jul 23, 2026
Database-update requests lacked consistent token and Super User checks, this could cause...
High
Unreviewed
CVE-2026-64876
was published
Jul 23, 2026
A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an...
High
Unreviewed
CVE-2024-58330
was published
Jul 23, 2026
Conditions administration did not consistently enforce tokens and component/mapped-item permissions.
High
Unreviewed
CVE-2026-63280
was published
Jul 22, 2026
Administrator actions, editor popups and import/export requests lacked consistent token, item...
High
Unreviewed
CVE-2026-63684
was published
Jul 22, 2026
Administrator routes and replacement requests did not consistently require Super User permission...
High
Unreviewed
CVE-2026-63685
was published
Jul 22, 2026
Administrator routes and install/update/uninstall processing did not consistently enforce...
High
Unreviewed
CVE-2026-64791
was published
Jul 22, 2026
Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching...
High
Unreviewed
CVE-2026-63265
was published
Jul 22, 2026
The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor...
High
Unreviewed
CVE-2026-63047
was published
Jul 22, 2026
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...
High
Unreviewed
CVE-2026-62574
was published
Jul 22, 2026
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll -...
High
Unreviewed
CVE-2026-62521
was published
Jul 22, 2026
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll)....
High
Unreviewed
CVE-2026-62557
was published
Jul 22, 2026
Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French...
High
Unreviewed
CVE-2026-62530
was published
Jul 22, 2026
Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E...
High
Unreviewed
CVE-2026-62514
was published
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API