GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,460
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,142
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
45 advisories
Filter by severity
saleor Missing Authorization vulnerability
Moderate
CVE-2022-0932
was published
for
saleor
(pip)
Mar 12, 2022
Missing Authorization in Apache Airflow
Moderate
CVE-2021-35936
was published
for
apache-airflow
(pip)
Aug 30, 2021
Permissions not properly checked in Invenio-Drafts-Resources
Moderate
CVE-2021-43781
was published
for
invenio-app-rdm
(pip)
Dec 6, 2021
MoinMoin improper access control on the included page for the rst parser
Moderate
CVE-2008-6548
was published
for
moin
(pip)
May 17, 2022
Privilege Escalation in Channelmgnt plug-in for Sopel
Moderate
CVE-2020-15251
was published
for
sopel-plugins-channelmgnt
(pip)
Oct 13, 2020
Code Injection, Race Condition, and Execution with Unnecessary Privileges in Ansible
Moderate
CVE-2020-10684
was published
for
ansible
(pip)
Apr 7, 2021
Improper Access Control in janeczku/calibre-web
Moderate
CVE-2021-3987
was published
for
calibreweb
(pip)
Nov 15, 2024
OpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests
Moderate
CVE-2014-0167
was published
for
nova
(pip)
May 17, 2022
Indico vulnerability allows attackers to bulk dump user details
Moderate
CVE-2025-53640
was published
for
indico
(pip)
Jul 14, 2025
copyparty: Sharing a single file does not fully restrict access to other files in source folder
Moderate
CVE-2025-58753
was published
for
copyparty
(pip)
Sep 9, 2025
Open WebUI Has Improper Access Control Leading to Arbitrary Prompt Read
Moderate
CVE-2024-7045
was published
for
open-webui
(pip)
Mar 20, 2025
Open WebUI Allows Viewing of Admin Details
Moderate
CVE-2024-7046
was published
for
open-webui
(pip)
Mar 20, 2025
Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning
Moderate
CVE-2025-69207
was published
for
khoj
(pip)
Feb 2, 2026
Wagtail has improper permission handling on admin preview endpoints
Moderate
CVE-2026-25517
was published
for
wagtail
(pip)
Feb 3, 2026
Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
Moderate
CVE-2026-27457
was published
for
weblate
(pip)
Feb 26, 2026
Apache Airflow: DAG Code and Import Error Permissions Ignored
Moderate
CVE-2024-27906
was published
for
apache-airflow
(pip)
Feb 29, 2024
litellm vulnerable to improper access control in team management
Moderate
CVE-2024-5710
was published
for
litellm
(pip)
Jun 27, 2024
Open WebUI has unauthorized deletion of knowledge files
Moderate
CVE-2026-29070
was published
for
open-webui
(pip)
Mar 27, 2026
openssl-encrypt has no owner verification on key revocation — any client can revoke any key
Moderate
GHSA-hvc7-763r-4f3h
was published
for
openssl-encrypt
(pip)
Apr 1, 2026
OpenViking contains a missing authorization vulnerability in the task polling endpoints
Moderate
CVE-2026-22680
was published
for
OpenViking
(pip)
Apr 7, 2026
PraisonAIAgents: Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate
Moderate
CVE-2026-40117
was published
for
praisonaiagents
(pip)
Apr 10, 2026
Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts
Moderate
CVE-2026-44550
was published
for
open-webui
(pip)
May 8, 2026
Open WebUI's Channel Access Grants Bypass filter_allowed_access_grants
Moderate
CVE-2026-44558
was published
for
open-webui
(pip)
May 8, 2026
ProTip!
Advisories are also available from the
GraphQL API