GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,948
Maven
5,000+
npm
5,000+
NuGet
969
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,383
Swift
56
Unreviewed advisories
All unreviewed
5,000+
125 advisories
Filter by severity
OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the ...
Critical
Unreviewed
CVE-2026-22234
was published
Jan 8, 2026
Affected devices do not properly enforce user authentication on specific API endpoints. This...
Critical
Unreviewed
CVE-2025-40805
was published
Jan 13, 2026
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is...
Critical
Unreviewed
CVE-2025-15521
was published
Jan 21, 2026
Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp...
Critical
Unreviewed
CVE-2026-24379
was published
Jan 22, 2026
An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home...
Critical
Unreviewed
CVE-2026-1201
was published
Jan 23, 2026
Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization
Critical
CVE-2026-26016
was published
for
pterodactyl/panel
(Composer)
Feb 17, 2026
An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited,...
Critical
Unreviewed
CVE-2025-40541
was published
Feb 24, 2026
SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows...
Critical
Unreviewed
CVE-2019-25487
was published
Mar 11, 2026
Winter vulnerable to privilege escalation by authenticated backend users
Critical
CVE-2026-27591
was published
for
winter/wn-backend-module
(Composer)
Mar 12, 2026
Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object...
Critical
Unreviewed
CVE-2017-20223
was published
Mar 16, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR
Critical
GHSA-2pv8-4c52-mf8j
was published
for
code.vikunja.io/api
(Go)
Mar 26, 2026
Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for...
Critical
Unreviewed
CVE-2026-1496
was published
Mar 27, 2026
A specific endpoint allows authenticated users to pivot to other user profiles by modifying the...
Critical
Unreviewed
CVE-2026-25197
was published
Apr 3, 2026
Paperclip: Cross-tenant agent API token minting via missing assertCompanyAccess on /api/agents/:id/keys
Critical
GHSA-47wq-cj9q-wpmp
was published
for
@paperclipai/server
(npm)
Apr 16, 2026
Paperclip: Cross-tenant agent API key IDOR in `/agents/:id/keys` routes allows full victim-company compromise
Critical
GHSA-3xx2-mqjm-hg9x
was published
for
@paperclipai/server
(npm)
Apr 16, 2026
An insecure direct object reference vulnerability in the Users API component of Crafty Controller...
Critical
Unreviewed
CVE-2026-5652
was published
Apr 21, 2026
ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated...
Critical
Unreviewed
CVE-2018-25270
was published
Apr 22, 2026
NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication...
Critical
Unreviewed
CVE-2026-24178
was published
Apr 28, 2026
A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20...
Critical
Unreviewed
CVE-2026-29200
was published
May 4, 2026
Insufficient ownership checks in `clientarea.php` allow an authenticated client area user to...
Critical
Unreviewed
CVE-2026-29204
was published
May 12, 2026
Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software...
Critical
Unreviewed
CVE-2026-2347
was published
May 14, 2026
Dify version 1.14.1 and prior contains an authorization bypass vulnerability that allows...
Critical
Unreviewed
CVE-2026-41947
was published
May 18, 2026
Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the ...
Critical
Unreviewed
CVE-2026-42097
was published
May 19, 2026
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path
Critical
GHSA-g53w-w6mj-hrpp
was published
for
github.com/Kuadrant/mcp-gateway
(Go)
May 19, 2026
PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation
Critical
CVE-2026-47407
was published
for
praisonai-platform
(pip)
May 29, 2026
ProTip!
Advisories are also available from the
GraphQL API