GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
193 advisories
Filter by severity
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
Low
CVE-2026-52839
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
Low
GHSA-pc2w-4mq8-32qw
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 29, 2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability...
Low
Unreviewed
CVE-2026-14821
was published
Jul 28, 2026
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Low
CVE-2026-59226
was published
for
open-webui
(pip)
Jul 24, 2026
ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check
Low
GHSA-v3j6-27vc-7pw2
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its...
Low
Unreviewed
CVE-2026-12690
was published
Jul 24, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation
Low
CVE-2026-58434
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
Low
CVE-2026-58438
was published
for
gitea.dev
(Go)
Jul 21, 2026
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element...
Low
Unreviewed
CVE-2026-16197
was published
Jul 19, 2026
A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is...
Low
Unreviewed
CVE-2026-16123
was published
Jul 18, 2026
A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function...
Low
Unreviewed
CVE-2026-16017
was published
Jul 17, 2026
The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its...
Low
Unreviewed
CVE-2026-12907
was published
Jul 16, 2026
Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned...
Low
Unreviewed
CVE-2026-9820
was published
Jul 13, 2026
A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an...
Low
Unreviewed
CVE-2026-15507
was published
Jul 13, 2026
A security flaw has been discovered in zhayujie CowAgent up to 2.1.0. The impacted element is an...
Low
Unreviewed
CVE-2026-15332
was published
Jul 10, 2026
A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulnerability affects the...
Low
Unreviewed
CVE-2026-15320
was published
Jul 10, 2026
Kiwi TCMS's /init-db/ page renders and responds to requests after first use
Low
CVE-2026-49292
was published
for
kiwitcms
(pip)
Jul 2, 2026
Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation
Low
GHSA-j5mc-p8qg-39j7
was published
for
kimai/kimai
(Composer)
Jul 2, 2026
OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
Low
GHSA-3wqp-prf6-2m72
was published
for
openclaw
(npm)
Jul 2, 2026
A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The...
Low
Unreviewed
CVE-2026-13484
was published
Jun 28, 2026
@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url
Low
GHSA-rp72-5v5q-2446
was published
for
@cardano402/mcp-server
(npm)
Jun 26, 2026
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
Low
Unreviewed
CVE-2026-57922
was published
Jun 26, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0...
Low
Unreviewed
CVE-2026-3176
was published
Jun 25, 2026
OliveTin: ValidateArgumentType API Endpoint's Missing Authentication Allows Action and Argument Enumeration
Low
CVE-2026-48709
was published
for
github.com/OliveTin/OliveTin
(Go)
Jun 24, 2026
Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL
Low
CVE-2026-55542
was published
for
snipe/snipe-it
(Composer)
Jun 23, 2026
ProTip!
Advisories are also available from the
GraphQL API