GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
149,672 advisories
Filter by severity
A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown...
Moderate
Unreviewed
CVE-2026-16327
was published
Jul 21, 2026
AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery...
Moderate
Unreviewed
CVE-2026-64626
was published
Jul 21, 2026
A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element...
Moderate
Unreviewed
CVE-2026-16324
was published
Jul 21, 2026
An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to...
Moderate
Unreviewed
CVE-2026-51385
was published
Jul 21, 2026
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-12900
was published
Jul 21, 2026
Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows...
Moderate
Unreviewed
CVE-2026-57852
was published
Jul 21, 2026
Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for...
Moderate
Unreviewed
CVE-2026-58624
was published
Jul 20, 2026
Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain...
Moderate
Unreviewed
CVE-2026-51026
was published
Jul 20, 2026
Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-26483
was published
Jul 20, 2026
The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that...
Moderate
Unreviewed
CVE-2026-58149
was published
Jul 17, 2026
Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string...
Moderate
Unreviewed
CVE-2026-9537
was published
Jul 17, 2026
HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows...
Moderate
Unreviewed
CVE-2026-63731
was published
Jul 20, 2026
Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url...
Moderate
Unreviewed
CVE-2026-63769
was published
Jul 20, 2026
Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to...
Moderate
Unreviewed
CVE-2026-63771
was published
Jul 20, 2026
cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback...
Moderate
Unreviewed
CVE-2026-63768
was published
Jul 20, 2026
HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows...
Moderate
Unreviewed
CVE-2026-63730
was published
Jul 20, 2026
The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Remote-URL download could...
Moderate
Unreviewed
CVE-2026-60033
was published
Jul 20, 2026
The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS...
Moderate
Unreviewed
CVE-2026-60029
was published
Jul 20, 2026
LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the...
Moderate
Unreviewed
CVE-2026-63107
was published
Jul 20, 2026
The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw...
Moderate
Unreviewed
CVE-2026-60031
was published
Jul 20, 2026
A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated...
Moderate
Unreviewed
CVE-2026-16252
was published
Jul 20, 2026
The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a...
Moderate
Unreviewed
CVE-2026-12898
was published
Jul 20, 2026
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order...
Moderate
Unreviewed
CVE-2026-12973
was published
Jul 20, 2026
LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the...
Moderate
Unreviewed
CVE-2025-45870
was published
Jul 16, 2026
A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking...
Moderate
Unreviewed
CVE-2026-50743
was published
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API