GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
43
Go
3,181
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,474
Pub
12
RubyGems
991
Rust
1,185
Swift
51
Unreviewed advisories
All unreviewed
5,000+
3,940 advisories
Filter by severity
In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace...
High
Unreviewed
CVE-2025-68623
was published
Mar 11, 2026
Keycloak: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API
Moderate
CVE-2026-3429
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 11, 2026
Parse Server has a protected fields bypass via dot-notation in query and sort
High
CVE-2026-31872
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server has role escalation and CLP bypass via direct `_Join` table write
Critical
CVE-2026-30966
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server has a protected fields bypass via logical query operators
High
CVE-2026-30962
was published
for
parse-server
(npm)
Mar 11, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
Moderate
CVE-2026-31815
was published
for
django-unicorn
(pip)
Mar 11, 2026
The register protection of the PowerVR GPU is incorrectly configured. This could lead to local...
Moderate
Unreviewed
CVE-2026-0108
was published
Mar 10, 2026
Vaadin Vulnerable to Authentication Bypass When Accessing the /VAADIN Endpoint Without a Trailing Slash
Moderate
CVE-2026-2742
was published
for
com.vaadin:flow-server
(Maven)
Mar 10, 2026
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized...
High
Unreviewed
CVE-2026-25176
was published
Mar 10, 2026
Improper access control in Windows Projected File System allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-24290
was published
Mar 10, 2026
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a...
High
Unreviewed
CVE-2026-21262
was published
Mar 10, 2026
Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to...
High
Unreviewed
CVE-2026-23660
was published
Mar 10, 2026
An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may...
Moderate
Unreviewed
CVE-2026-22628
was published
Mar 10, 2026
An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An...
High
Unreviewed
CVE-2026-30140
was published
Mar 9, 2026
OpenClaw: Sandboxed /acp spawn requests could initialize host ACP sessions
Moderate
GHSA-9q36-67vc-rrwg
was published
for
openclaw
(npm)
Mar 9, 2026
SiYuan: Authorization Bypass Allows Low-Privilege Publish User to Modify Notebook Content via /api/block/appendHeadingChildren
High
CVE-2026-30926
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 9, 2026
A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected...
Moderate
Unreviewed
CVE-2026-3800
was published
Mar 9, 2026
A security vulnerability has been detected in Tiandy Video Surveillance System 视频监控平台 7.17.0. The...
Moderate
Unreviewed
CVE-2026-3797
was published
Mar 9, 2026
A security flaw has been discovered in Bytedesk up to 1.3.9. This affects the function uploadFile...
Moderate
Unreviewed
CVE-2026-3748
was published
Mar 8, 2026
A weakness has been identified in Bytedesk up to 1.3.9. This vulnerability affects the function...
Moderate
Unreviewed
CVE-2026-3749
was published
Mar 8, 2026
WeKnora has Broken Access Control - Cross-Tenant Data Exposure
High
CVE-2026-30859
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 6, 2026
WeKnora Vulnerable to Broken Access Control in Tenant Management
Critical
CVE-2026-30855
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 6, 2026
Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x...
High
Unreviewed
CVE-2025-70363
was published
Mar 6, 2026
Plane is Vulnerable to Unauthenticated Workspace Member Information Disclosure
High
CVE-2026-30244
was published
for
plane
(pip)
Mar 5, 2026
OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control...
High
Unreviewed
CVE-2025-70614
was published
Mar 5, 2026
ProTip!
Advisories are also available from the
GraphQL API