GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,569
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,522
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
168,549 advisories
Filter by severity
The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary...
Moderate
Unreviewed
CVE-2026-75982
was published
Aug 25, 2026
The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-9878
was published
Aug 25, 2026
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-10627
was published
Aug 25, 2026
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks &...
Moderate
Unreviewed
CVE-2026-75019
was published
Aug 25, 2026
Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an...
Moderate
Unreviewed
CVE-2026-75575
was published
Aug 25, 2026
Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non...
Moderate
Unreviewed
CVE-2026-72701
was published
Aug 25, 2026
Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked...
Moderate
Unreviewed
CVE-2026-56706
was published
Aug 25, 2026
Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER[...
Moderate
Unreviewed
CVE-2026-34959
was published
Aug 25, 2026
Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with...
Moderate
Unreviewed
CVE-2026-56704
was published
Aug 25, 2026
Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file...
Moderate
Unreviewed
CVE-2026-34967
was published
Aug 25, 2026
Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's...
Moderate
Unreviewed
CVE-2026-34964
was published
Aug 25, 2026
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-15023
was published
Aug 25, 2026
The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin...
Moderate
Unreviewed
CVE-2026-19801
was published
Aug 25, 2026
Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook...
Moderate
Unreviewed
CVE-2026-56708
was published
Aug 25, 2026
The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education...
Moderate
Unreviewed
CVE-2026-10630
was published
Aug 25, 2026
A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController:...
Moderate
Unreviewed
CVE-2026-78434
was published
Aug 25, 2026
Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
Moderate
Unreviewed
CVE-2026-78266
was published
Aug 25, 2026
Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.
Moderate
Unreviewed
CVE-2026-27364
was published
Aug 25, 2026
vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
Moderate
GHSA-fx4f-mhw4-qm7j
was published
for
vibeio-http
(Rust)
Aug 24, 2026
Cloudreve's remote download file paths can escape the selected destination directory
Moderate
GHSA-w8j7-39hp-8x59
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Aug 24, 2026
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
Moderate
GHSA-vx2m-jpxr-xv7w
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Aug 24, 2026
A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an...
Moderate
Unreviewed
CVE-2026-5006
was published
Aug 24, 2026
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled...
Moderate
Unreviewed
CVE-2026-16781
was published
Aug 24, 2026
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds...
Moderate
Unreviewed
CVE-2026-16782
was published
Aug 24, 2026
Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an...
Moderate
Unreviewed
CVE-2026-77923
was published
Aug 24, 2026
ProTip!
Advisories are also available from the
GraphQL API