GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
135 advisories
Filter by severity
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer:...
Critical
Unreviewed
CVE-2026-86153
was published
Sep 6, 2026
Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
Critical
Unreviewed
CVE-2026-84814
was published
Sep 3, 2026
Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
Critical
Unreviewed
CVE-2026-81294
was published
Sep 2, 2026
A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the...
Critical
Unreviewed
CVE-2026-82628
was published
Aug 31, 2026
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2...
Critical
Unreviewed
CVE-2026-32566
was published
Aug 27, 2026
The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and...
Critical
Unreviewed
CVE-2026-78477
was published
Aug 25, 2026
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
Critical
Unreviewed
CVE-2026-78267
was published
Aug 25, 2026
Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce &...
Critical
Unreviewed
CVE-2026-32558
was published
Aug 24, 2026
Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
Critical
Unreviewed
CVE-2026-28165
was published
Aug 24, 2026
Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
Critical
Unreviewed
CVE-2026-66648
was published
Aug 24, 2026
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
Critical
Unreviewed
CVE-2026-66682
was published
Aug 20, 2026
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
Critical
Unreviewed
CVE-2025-15689
was published
Aug 20, 2026
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active...
Critical
Unreviewed
CVE-2026-11861
was published
Aug 20, 2026
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.
Critical
Unreviewed
CVE-2026-73347
was published
Aug 19, 2026
Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
Critical
Unreviewed
CVE-2026-73390
was published
Aug 19, 2026
The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly...
Critical
Unreviewed
CVE-2026-72826
was published
Aug 14, 2026
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is...
Critical
Unreviewed
CVE-2026-72839
was published
Aug 14, 2026
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
Critical
Unreviewed
CVE-2026-66424
was published
Aug 13, 2026
Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a...
Critical
Unreviewed
CVE-2026-64639
was published
Aug 12, 2026
Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
Critical
Unreviewed
CVE-2026-66662
was published
Aug 6, 2026
Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
Critical
Unreviewed
CVE-2026-65507
was published
Aug 6, 2026
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant...
Critical
Unreviewed
CVE-2026-10059
was published
Aug 5, 2026
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
Critical
Unreviewed
CVE-2026-61951
was published
Jul 23, 2026
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.
Critical
Unreviewed
CVE-2026-59540
was published
Jul 23, 2026
Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows...
Critical
Unreviewed
CVE-2026-57813
was published
Jul 13, 2026
ProTip!
Advisories are also available from the
GraphQL API