GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,948
Maven
5,000+
npm
5,000+
NuGet
969
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,383
Swift
56
Unreviewed advisories
All unreviewed
5,000+
838 advisories
Filter by severity
The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched...
Moderate
Unreviewed
CVE-2026-46764
was published
Jun 1, 2026
Authorization Bypass Through User-Controlled Key vulnerability in Vidco Software VOC TESTER...
Moderate
Unreviewed
CVE-2024-13175
was published
Jul 18, 2025
Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft MyRezzta allows...
Moderate
Unreviewed
CVE-2024-13063
was published
Jun 1, 2026
praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership
Moderate
CVE-2026-47408
was published
for
praisonai-platform
(pip)
May 29, 2026
Admidio: IDOR in documents-files.php allows cross-folder file rename and description changes by unauthorized uploaders
Moderate
CVE-2026-47230
was published
for
admidio/admidio
(Composer)
May 29, 2026
Admidio module-administrator can delete or reorder categories owned by other modules via dead authorization check in `modules/categories.php`
Moderate
CVE-2026-47227
was published
for
admidio/admidio
(Composer)
May 29, 2026
Admidio: Authorization bypass in file_delete enables cross-folder file removal by authenticated users without delete privileges
Moderate
CVE-2026-47226
was published
for
admidio/admidio
(Composer)
May 29, 2026
In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of...
Moderate
Unreviewed
CVE-2026-49386
was published
May 29, 2026
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction,...
Moderate
Unreviewed
CVE-2026-7651
was published
May 28, 2026
The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in...
Moderate
Unreviewed
CVE-2026-3173
was published
May 28, 2026
The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure...
Moderate
Unreviewed
CVE-2026-9228
was published
May 28, 2026
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-9241
was published
May 28, 2026
Authorization Bypass Through User-Controlled Key vulnerability in WP Wham Checkout Files Upload...
Moderate
Unreviewed
CVE-2026-42725
was published
May 27, 2026
An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace...
Moderate
Unreviewed
CVE-2026-38587
was published
May 26, 2026
Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend...
Moderate
Unreviewed
CVE-2026-8204
was published
May 21, 2026
OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key...
Moderate
Unreviewed
CVE-2026-40127
was published
May 26, 2026
Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express...
Moderate
Unreviewed
CVE-2026-7881
was published
May 22, 2026
The Broadstreet plugin for WordPress is vulnerable to Insecure Direct Object Reference in all...
Moderate
Unreviewed
CVE-2026-1881
was published
May 21, 2026
A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can...
Moderate
Unreviewed
CVE-2026-37978
was published
May 19, 2026
A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId...
Moderate
Unreviewed
CVE-2026-9087
was published
May 20, 2026
The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-6566
was published
May 20, 2026
The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-6072
was published
May 20, 2026
MantisBT Has Authorization Bypass in Global Profile Creation
Moderate
CVE-2026-33052
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
Open WebUI has an Indirect Object Reference (IDOR) in user notes
Moderate
CVE-2026-45666
was published
for
open-webui
(pip)
May 14, 2026
OpenClaw: Hook mapping templates could bypass hook session-key opt-in
Moderate
CVE-2026-45002
was published
for
openclaw
(npm)
Apr 25, 2026
ProTip!
Advisories are also available from the
GraphQL API