GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
330 advisories
Filter by severity
Netty: Security Control Bypass via CORS Short-Circuit Failure
Moderate
CVE-2026-56746
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
Moderate
CVE-2026-58429
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint
Moderate
CVE-2026-58507
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Decidim: Forms admin question editor lacks authorization
Moderate
CVE-2026-45086
was published
for
decidim-demographics
(RubyGems)
Jul 13, 2026
Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
Moderate
GHSA-382c-vx95-w3p5
was published
for
@jsonbored/gittensory-mcp
(npm)
Jul 9, 2026
Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check
Moderate
CVE-2026-50280
was published
for
craftcms/cms
(Composer)
Jul 2, 2026
OpenClaw's browser act interactions could bypass private-network navigation checks
Moderate
CVE-2026-53812
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn
Moderate
GHSA-qh2f-99mv-mrcf
was published
for
openclaw
(npm)
Jul 2, 2026
Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing
Moderate
CVE-2026-53520
was published
for
github.com/nezhahq/nezha
(Go)
Jun 26, 2026
GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion
Moderate
CVE-2026-48529
was published
for
github.com/github/github-mcp-server
(Go)
Jun 25, 2026
motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint
Moderate
CVE-2026-31978
was published
for
motioneye
(pip)
Jun 22, 2026
OpenCTI May Bypass Introspection Restriction
Moderate
CVE-2024-37155
was published
for
pycti
(pip)
Jun 22, 2026
Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
Moderate
CVE-2026-54015
was published
for
open-webui
(pip)
Jun 17, 2026
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
Moderate
CVE-2026-54761
was published
for
github.com/traefik/traefik
(Go)
Jun 17, 2026
Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
Moderate
CVE-2026-49411
was published
for
deno
(Rust)
Jun 16, 2026
n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
Moderate
GHSA-hv7x-3x78-gx53
was published
for
n8n
(npm)
Jun 16, 2026
vantage6 node has an Improper Access Control issue
Moderate
CVE-2026-54533
was published
for
vantage6
(pip)
Jun 5, 2026
NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints
Moderate
CVE-2026-47279
was published
for
nocodb
(npm)
Jun 5, 2026
MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions
Moderate
CVE-2026-3198
was published
for
mlflow
(pip)
Jun 2, 2026
Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`
Moderate
CVE-2026-47200
was published
for
@nuxt/nitro-server
(npm)
May 29, 2026
@koa/router has an Access Control Bypass
Moderate
CVE-2026-9495
was published
for
@koa/router
(npm)
May 26, 2026
Concrete CMS is vulnerable to unauthenticated page metadata disclosure
Moderate
CVE-2026-8240
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks
Moderate
CVE-2026-2734
was published
for
mlflow
(pip)
May 21, 2026
AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`
Moderate
CVE-2026-46337
was published
for
WWBN/AVideo
(Composer)
May 19, 2026
Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass
Moderate
CVE-2026-37979
was published
for
org.keycloak:keycloak-services
(Maven)
May 19, 2026
ProTip!
Advisories are also available from the
GraphQL API