GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
164,286 advisories
Filter by severity
A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated...
Moderate
Unreviewed
CVE-2026-16252
was published
Jul 20, 2026
The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a...
Moderate
Unreviewed
CVE-2026-12898
was published
Jul 20, 2026
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order...
Moderate
Unreviewed
CVE-2026-12973
was published
Jul 20, 2026
LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the...
Moderate
Unreviewed
CVE-2025-45870
was published
Jul 16, 2026
A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking...
Moderate
Unreviewed
CVE-2026-50743
was published
Jul 20, 2026
Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies...
Moderate
Unreviewed
CVE-2026-13724
was published
Jul 20, 2026
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN...
Moderate
Unreviewed
CVE-2026-26081
was published
Jul 20, 2026
Improper neutralization of input during web page generation ('cross-site scripting')...
Moderate
Unreviewed
CVE-2026-6793
was published
Jul 20, 2026
rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated...
Moderate
Unreviewed
CVE-2026-63102
was published
Jul 20, 2026
The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its...
Moderate
Unreviewed
CVE-2026-12723
was published
Jul 20, 2026
The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body...
Moderate
Unreviewed
CVE-2026-12724
was published
Jul 20, 2026
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order...
Moderate
Unreviewed
CVE-2026-12972
was published
Jul 20, 2026
Axios: Excessive recursion in formDataToJSON can cause denial of service
Moderate
GHSA-42h9-826w-cgv3
was published
for
axios
(npm)
Jul 20, 2026
Axios: Prototype pollution auth subfields can inject Basic auth
Moderate
GHSA-xj6q-8x83-jv6g
was published
for
axios
(npm)
Jul 20, 2026
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
Moderate
GHSA-pmv8-rq9r-6j72
was published
for
axios
(npm)
Jul 20, 2026
The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its...
Moderate
Unreviewed
CVE-2026-13432
was published
Jul 20, 2026
Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview...
Moderate
Unreviewed
CVE-2026-59238
was published
Jul 20, 2026
A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote...
Moderate
Unreviewed
CVE-2026-16277
was published
Jul 20, 2026
Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords....
Moderate
Unreviewed
CVE-2026-57310
was published
Jul 20, 2026
Windu CMS does not validate types of uploaded files. An authenticated attacker can upload...
Moderate
Unreviewed
CVE-2026-57311
was published
Jul 20, 2026
The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration...
Moderate
Unreviewed
CVE-2026-13156
was published
Jul 20, 2026
The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on...
Moderate
Unreviewed
CVE-2026-11868
was published
Jul 20, 2026
The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes...
Moderate
Unreviewed
CVE-2026-10724
was published
Jul 20, 2026
The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user...
Moderate
Unreviewed
CVE-2026-8825
was published
Jul 20, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM...
Moderate
Unreviewed
CVE-2026-3602
was published
Jun 30, 2026
ProTip!
Advisories are also available from the
GraphQL API