GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,948
Maven
5,000+
npm
5,000+
NuGet
969
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,383
Swift
56
Unreviewed advisories
All unreviewed
5,000+
299 advisories
Filter by severity
wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data
Low
CVE-2026-27838
was published
for
wger
(pip)
Feb 26, 2026
wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data
Moderate
CVE-2026-27835
was published
for
wger
(pip)
Feb 26, 2026
OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting
High
CVE-2026-28469
was published
for
clawdbot
(npm)
Feb 18, 2026
Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization
Critical
CVE-2026-26016
was published
for
pterodactyl/panel
(Composer)
Feb 17, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment
Moderate
CVE-2026-25120
was published
for
gogs.io/gogs
(Go)
Feb 17, 2026
OpenClaw Hook Session Key Override Enables Targeted Cross-Session Routing
High
GHSA-hv93-r4j3-q65f
was published
for
openclaw
(npm)
Feb 17, 2026
Craft CMS: GraphQL Asset Mutation Privilege Escalation
High
CVE-2026-25497
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Unauthenticated Spree Commerce users can access all guest addresses
High
CVE-2026-25758
was published
for
spree_api
(RubyGems)
Feb 5, 2026
Unauthenticated Spree Commerce users can view completed guest orders by Order ID
High
CVE-2026-25757
was published
for
spree_storefront
(RubyGems)
Feb 5, 2026
payload-preferences has Cross-Collection IDOR in Access Control (Multi-Auth Environments)
Moderate
CVE-2026-25574
was published
for
payload
(npm)
Feb 5, 2026
pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability
High
CVE-2026-1707
was published
for
pgadmin4
(pip)
Feb 5, 2026
Cloudflare Agents SDK has Insecure Direct Object Reference (IDOR) via Header-Based Email Routing
Moderate
CVE-2026-1664
was published
for
agents
(npm)
Feb 3, 2026
Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning
Moderate
CVE-2025-69207
was published
for
khoj
(pip)
Feb 2, 2026
StudioCMS has Authorization Bypass Through User-Controlled Key
Moderate
CVE-2026-24134
was published
for
studiocms
(npm)
Jan 27, 2026
askbot inexhaustive permissions check allows any user to modify a different user's profile picture
Moderate
CVE-2026-1213
was published
for
askbot
(pip)
Jan 27, 2026
Dozzle Agent Label-Based Access Control Bypass Allows Unauthorized Container Shell Access
High
CVE-2026-24740
was published
for
github.com/amir20/dozzle
(Go)
Jan 27, 2026
Chainlit contains an authorization bypass vulnerability
Low
CVE-2025-68492
was published
for
chainlit
(pip)
Jan 14, 2026
Spree API has Unauthenticated IDOR - Guest Address
High
CVE-2026-22589
was published
for
spree_core
(RubyGems)
Jan 8, 2026
Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification
Moderate
CVE-2026-22588
was published
for
spree_api
(RubyGems)
Jan 8, 2026
Bagisto has IDOR in Customer Order Reorder Functionality
High
CVE-2026-21447
was published
for
bagisto/bagisto
(Composer)
Jan 2, 2026
axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header
Moderate
CVE-2025-69202
was published
for
axios-cache-interceptor
(npm)
Dec 30, 2025
pretix has Broken Access Control Allowing Cross-User File Access via UUID
Low
CVE-2025-14881
was published
for
pretix
(pip)
Dec 19, 2025
pretix has Broken Access Control Allowing Cross-User File Access via UUID
Low
CVE-2025-14882
was published
for
pretix
(pip)
Dec 19, 2025
Pagekit CMS has an Insecure Direct Object Reference (IDOR) in its User Role component
Critical
CVE-2025-67165
was published
for
pagekit/pagekit
(Composer)
Dec 17, 2025
Grav vulnerable to Information Disclosure via IDOR in Grav Admin Panel
Moderate
CVE-2025-66306
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
ProTip!
Advisories are also available from the
GraphQL API