GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,771
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
172,339 advisories
Filter by severity
A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue...
Moderate
Unreviewed
CVE-2026-93371
was published
Sep 18, 2026
The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2026-15650
was published
Sep 18, 2026
The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the...
Moderate
Unreviewed
CVE-2026-92991
was published
Sep 18, 2026
The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css...
Moderate
Unreviewed
CVE-2026-14855
was published
Sep 18, 2026
The Approval app's approve/reject endpoint is meant to require the file's current etag as a...
Moderate
Unreviewed
CVE-2026-82982
was published
Sep 18, 2026
The Deck config API allows authenticated users to set board-scoped configuration keys for...
Moderate
Unreviewed
CVE-2026-77170
was published
Sep 18, 2026
The Photos app's filter-based "smart albums" build their file listing using the search...
Moderate
Unreviewed
CVE-2026-82985
was published
Sep 18, 2026
A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function...
Moderate
Unreviewed
CVE-2026-93331
was published
Sep 18, 2026
Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV...
Moderate
Unreviewed
CVE-2026-82980
was published
Sep 18, 2026
A vulnerability in the team folders (formerly group folders) app when used in combination with...
Moderate
Unreviewed
CVE-2026-77169
was published
Sep 18, 2026
A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of...
Moderate
Unreviewed
CVE-2026-93310
was published
Sep 18, 2026
Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before...
Moderate
Unreviewed
CVE-2026-77164
was published
Sep 18, 2026
Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw...
Moderate
Unreviewed
CVE-2026-93454
was published
Sep 18, 2026
snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress...
Moderate
Unreviewed
CVE-2026-93451
was published
Sep 18, 2026
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2026-2585
was published
Sep 18, 2026
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for...
Moderate
Unreviewed
CVE-2026-18441
was published
Sep 18, 2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft...
Moderate
Unreviewed
CVE-2026-55946
was published
Sep 18, 2026
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-16750
was published
Sep 18, 2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-14311
was published
Sep 18, 2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-16582
was published
Sep 18, 2026
A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the...
Moderate
Unreviewed
CVE-2026-93394
was published
Sep 17, 2026
A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an...
Moderate
Unreviewed
CVE-2026-93395
was published
Sep 17, 2026
HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when...
Moderate
Unreviewed
CVE-2026-67071
was published
Sep 17, 2026
Applications built on MongoDB Entity Framework Core Provider which combine independent encryption...
Moderate
Unreviewed
CVE-2026-92756
was published
Sep 17, 2026
Applications built on MongoDB Entity Framework Core Provider which place a database name in the...
Moderate
Unreviewed
CVE-2026-92757
was published
Sep 17, 2026
ProTip!
Advisories are also available from the
GraphQL API