GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,948
Maven
5,000+
npm
5,000+
NuGet
969
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,383
Swift
56
Unreviewed advisories
All unreviewed
5,000+
125 advisories
Filter by severity
PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation
Critical
CVE-2026-47407
was published
for
praisonai-platform
(pip)
May 29, 2026
Dify version 1.14.1 and prior contains an authorization bypass vulnerability that allows...
Critical
Unreviewed
CVE-2026-41947
was published
May 18, 2026
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path
Critical
GHSA-g53w-w6mj-hrpp
was published
for
github.com/Kuadrant/mcp-gateway
(Go)
May 19, 2026
Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the ...
Critical
Unreviewed
CVE-2026-42097
was published
May 19, 2026
Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software...
Critical
Unreviewed
CVE-2026-2347
was published
May 14, 2026
Insufficient ownership checks in `clientarea.php` allow an authenticated client area user to...
Critical
Unreviewed
CVE-2026-29204
was published
May 12, 2026
A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20...
Critical
Unreviewed
CVE-2026-29200
was published
May 4, 2026
NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication...
Critical
Unreviewed
CVE-2026-24178
was published
Apr 28, 2026
Authorization Bypass Through User-Controlled Key vulnerability in Ricard Torres Thumbs Rating...
Critical
Unreviewed
CVE-2024-31095
was published
Mar 31, 2024
ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated...
Critical
Unreviewed
CVE-2018-25270
was published
Apr 22, 2026
An insecure direct object reference vulnerability in the Users API component of Crafty Controller...
Critical
Unreviewed
CVE-2026-5652
was published
Apr 21, 2026
Paperclip: Cross-tenant agent API key IDOR in `/agents/:id/keys` routes allows full victim-company compromise
Critical
GHSA-3xx2-mqjm-hg9x
was published
for
@paperclipai/server
(npm)
Apr 16, 2026
Paperclip: Cross-tenant agent API token minting via missing assertCompanyAccess on /api/agents/:id/keys
Critical
GHSA-47wq-cj9q-wpmp
was published
for
@paperclipai/server
(npm)
Apr 16, 2026
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress...
Critical
Unreviewed
CVE-2023-6875
was published
Jan 11, 2024
The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via...
Critical
Unreviewed
CVE-2024-8485
was published
Sep 25, 2024
The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and...
Critical
Unreviewed
CVE-2024-2472
was published
Jun 14, 2024
A specific endpoint allows authenticated users to pivot to other user profiles by modifying the...
Critical
Unreviewed
CVE-2026-25197
was published
Apr 3, 2026
Authorization Bypass Through User-Controlled Key vulnerability in Meetup allows Privilege...
Critical
Unreviewed
CVE-2024-50483
was published
Oct 28, 2024
Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for...
Critical
Unreviewed
CVE-2026-1496
was published
Mar 27, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR
Critical
GHSA-2pv8-4c52-mf8j
was published
for
code.vikunja.io/api
(Go)
Mar 26, 2026
Authorization Bypass Through User-Controlled Key in go-zero
Critical
CVE-2024-27302
was published
for
github.com/zeromicro/go-zero
(Go)
Mar 4, 2024
Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object...
Critical
Unreviewed
CVE-2017-20223
was published
Mar 16, 2026
Winter vulnerable to privilege escalation by authenticated backend users
Critical
CVE-2026-27591
was published
for
winter/wn-backend-module
(Composer)
Mar 12, 2026
SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows...
Critical
Unreviewed
CVE-2019-25487
was published
Mar 11, 2026
An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited,...
Critical
Unreviewed
CVE-2025-40541
was published
Feb 24, 2026
ProTip!
Advisories are also available from the
GraphQL API