GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
8,206 advisories
Filter by severity
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
Low
CVE-2026-52839
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
Low
GHSA-pc2w-4mq8-32qw
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 29, 2026
The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification...
Moderate
Unreviewed
CVE-2026-4604
was published
Jul 29, 2026
The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the...
Critical
Unreviewed
CVE-2026-14488
was published
Jul 29, 2026
Description:
Missing Authorization in Apache Atlas.
A missing authorization vulnerability in...
High
Unreviewed
CVE-2026-50622
was published
Jul 29, 2026
Keycloak provides a way to manage identity providers and organizations through its administrative...
Moderate
Unreviewed
CVE-2026-18201
was published
Jul 29, 2026
The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not verify the payment-gateway...
Moderate
Unreviewed
CVE-2026-13692
was published
Jul 29, 2026
The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a...
Moderate
Unreviewed
CVE-2026-5626
was published
Jul 29, 2026
The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event...
Moderate
Unreviewed
CVE-2026-17166
was published
Jul 29, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
High
CVE-2026-54719
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass...
High
Unreviewed
CVE-2026-16184
was published
Jul 28, 2026
Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any...
Moderate
Unreviewed
CVE-2026-66751
was published
Jul 28, 2026
Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows...
Moderate
Unreviewed
CVE-2026-66750
was published
Jul 28, 2026
The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in...
Moderate
Unreviewed
CVE-2026-13110
was published
Jul 28, 2026
The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View...
Moderate
Unreviewed
CVE-2026-15411
was published
Jul 28, 2026
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for...
High
Unreviewed
CVE-2026-15025
was published
Jul 28, 2026
The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and...
Moderate
Unreviewed
CVE-2026-16774
was published
Jul 28, 2026
A low privileged remote attacker can gain administrator privileges due to missing authorization...
High
Unreviewed
CVE-2026-14168
was published
Jul 28, 2026
The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice...
Moderate
Unreviewed
CVE-2026-12124
was published
Jul 28, 2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability...
Low
Unreviewed
CVE-2026-14821
was published
Jul 28, 2026
The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication,...
High
Unreviewed
CVE-2026-14924
was published
Jul 28, 2026
The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-16587
was published
Jul 28, 2026
Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.
Moderate
Unreviewed
CVE-2026-65445
was published
Jul 28, 2026
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
High
Unreviewed
CVE-2026-66473
was published
Jul 28, 2026
An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.6...
Critical
Unreviewed
CVE-2026-64746
was published
Jul 27, 2026
ProTip!
Advisories are also available from the
GraphQL API