GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
47
GitHub Actions
48
Go
3,378
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,573
Pub
13
RubyGems
1,013
Rust
1,205
Swift
51
Unreviewed advisories
All unreviewed
5,000+
304 advisories
Filter by severity
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
High
CVE-2026-32716
was published
for
scitokens
(pip)
Mar 31, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation
High
CVE-2026-33680
was published
for
code.vikunja.io/api
(Go)
Mar 25, 2026
Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
High
GHSA-46wh-3698-f2cx
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 29, 2026
The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
High
Unreviewed
CVE-2026-4248
was published
Mar 28, 2026
An authentication issue was addressed with improved state management. This issue is fixed in iOS...
High
Unreviewed
CVE-2026-28865
was published
Mar 25, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect
High
CVE-2026-33668
was published
for
code.vikunja.io/api
(Go)
Mar 25, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
High
CVE-2026-32300
was published
for
opensource-workshop/connect-cms
(Composer)
Mar 23, 2026
OpenClaw DM pairing-store identities could satisfy group allowlist authorization
High
CVE-2026-32027
was published
for
openclaw
(npm)
Mar 3, 2026
Frigte has broken access control viewer user can delete admin and other users account
High
CVE-2026-33125
was published
for
frigate
(pip)
Mar 18, 2026
Juju has unauthorized update of out-of-scope Vault secrets
High
CVE-2026-32692
was published
for
github.com/juju/juju
(Go)
Mar 19, 2026
OpenClaw: Command-authorized non-owners could reach owner-only `/config` and `/debug` surfaces
High
GHSA-r7vr-gr74-94p8
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw Twitch allowFrom is not enforced in optional plugin, unauthorized chat users can trigger agent pipeline
High
CVE-2026-28448
was published
for
openclaw
(npm)
Feb 17, 2026
Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administrator
High
CVE-2026-3009
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 5, 2026
OpenClaw Slack: dmPolicy=open allowed any DM sender to run privileged slash commands
High
CVE-2026-28392
was published
for
openclaw
(npm)
Feb 18, 2026
In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to...
High
Unreviewed
CVE-2026-0017
was published
Mar 2, 2026
Vaultwarden's Collection Management Operations Allowed Without `manage` Verification for Manager Role
High
CVE-2026-27803
was published
for
vaultwarden
(Rust)
Mar 4, 2026
INSATutorat has an authorization bypass vulnerability in its /api/admin/* endpoints
High
GHSA-xfx2-prg5-jq3g
was published
for
github.com/romitou/insatutorat
(Go)
Mar 1, 2026
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is...
High
Unreviewed
CVE-2025-4521
was published
Feb 19, 2026
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over...
High
Unreviewed
CVE-2026-20960
was published
Jan 17, 2026
Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before...
High
Unreviewed
CVE-2024-50617
was published
Feb 12, 2026
File Browser is Vulnerable to Insecure Direct Object Reference (IDOR) in Share Deletion Function
High
CVE-2025-64523
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Nov 13, 2025
Finality Provider vulnerable to anti-slashing bypassing due to misconfiguration
High
GHSA-4jmp-x7mh-rgmr
was published
for
github.com/babylonlabs-io/finality-provider
(Go)
Dec 12, 2025
Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin
High
CVE-2026-22022
was published
for
org.apache.solr:solr-core
(Maven)
Jan 21, 2026
HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass...
High
Unreviewed
CVE-2026-21641
was published
Jan 20, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
High
CVE-2026-22033
was published
for
label-studio
(pip)
Jan 12, 2026
ProTip!
Advisories are also available from the
GraphQL API