GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
164,286 advisories
Filter by severity
The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard...
Moderate
Unreviewed
CVE-2026-15379
was published
Jul 17, 2026
The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-9656
was published
Jul 17, 2026
The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability...
Moderate
Unreviewed
CVE-2026-11966
was published
Jul 17, 2026
The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking...
Moderate
Unreviewed
CVE-2026-12393
was published
Jul 17, 2026
The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status...
Moderate
Unreviewed
CVE-2026-13402
was published
Jul 17, 2026
The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form...
Moderate
Unreviewed
CVE-2026-10525
was published
Jul 17, 2026
Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo.
An authenticated,...
Moderate
Unreviewed
CVE-2026-62764
was published
Jul 17, 2026
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-15457
was published
Jul 17, 2026
The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for...
Moderate
Unreviewed
CVE-2026-15759
was published
Jul 17, 2026
The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2026-15094
was published
Jul 17, 2026
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-15349
was published
Jul 17, 2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which...
Moderate
Unreviewed
CVE-2026-21770
was published
Jul 17, 2026
Improper Access Control vulnerability in the Removable Media Validation function of TXOne...
Moderate
Unreviewed
CVE-2026-41993
was published
Jul 17, 2026
Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2...
Moderate
Unreviewed
CVE-2026-60060
was published
Jul 17, 2026
Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term...
Moderate
Unreviewed
CVE-2026-58317
was published
Jul 17, 2026
The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are...
Moderate
Unreviewed
CVE-2026-11324
was published
Jul 17, 2026
The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Moderate
Unreviewed
CVE-2026-14503
was published
Jul 17, 2026
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all...
Moderate
Unreviewed
CVE-2026-15160
was published
Jul 17, 2026
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2026-15161
was published
Jul 17, 2026
The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of...
Moderate
Unreviewed
CVE-2026-8616
was published
Jul 17, 2026
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object...
Moderate
Unreviewed
CVE-2026-15159
was published
Jul 17, 2026
Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the...
Moderate
Unreviewed
CVE-2026-62237
was published
Jul 17, 2026
OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks...
Moderate
Unreviewed
CVE-2026-62219
was published
Jul 17, 2026
OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass...
Moderate
Unreviewed
CVE-2026-62220
was published
Jul 17, 2026
OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser...
Moderate
Unreviewed
CVE-2026-62226
was published
Jul 17, 2026
ProTip!
Advisories are also available from the
GraphQL API