GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,175
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
34 advisories
Filter by severity
CKAN contains Improper Authentication leading to account takeover
High
CVE-2022-43685
was published
for
ckan
(pip)
Nov 22, 2022
pgadmin4 vulnerable to Code Injection
High
CVE-2022-4223
was published
for
pgadmin4
(pip)
Dec 13, 2022
Synapse does not apply enough checks to servers requesting auth events of events in a room
High
CVE-2022-39335
was published
for
matrix-synapse
(pip)
May 24, 2023
Apache Airflow: Bypass permission verification to read code of other dags
High
CVE-2023-50944
was published
for
apache-airflow
(pip)
Jan 24, 2024
Open WebUI Allows Arbitrary File Reading and Deletion
High
CVE-2024-7043
was published
for
open-webui
(pip)
Mar 20, 2025
Backend.AI Missing Authorization vulnerability
High
CVE-2025-49651
was published
for
backend.ai
(pip)
Jun 9, 2025
Fides Webserver API is Vulnerable to OAuth Client Privilege Escalation
High
CVE-2025-57817
was published
for
ethyca-fides
(pip)
Sep 8, 2025
Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization
High
CVE-2026-30911
was published
for
apache-airflow
(pip)
Mar 17, 2026
langflow has Unauthenticated IDOR on Image Downloads
High
CVE-2026-33484
was published
for
langflow
(pip)
Mar 20, 2026
Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
High
CVE-2026-34046
was published
for
langflow
(pip)
Mar 27, 2026
Ajenti has an authorization bypass during custom package installation
High
CVE-2026-35175
was published
for
ajenti-panel
(pip)
Apr 3, 2026
wger has Broken Access Control in Global Gym Configuration Update Endpoint
High
CVE-2026-40474
was published
for
wger
(pip)
Apr 16, 2026
Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining
High
CVE-2026-44555
was published
for
open-webui
(pip)
May 8, 2026
Open WebUI's responses passthrough endpoint lacks access control authorization
High
CVE-2026-44556
was published
for
open-webui
(pip)
May 8, 2026
Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite
High
CVE-2026-44554
was published
for
open-webui
(pip)
May 8, 2026
Open WebUI has Improper Authorization Control
High
CVE-2026-44567
was published
for
open-webui
(pip)
May 8, 2026
Open WebUI's Insecure Message Access Breaks Authorization
High
CVE-2026-44569
was published
for
open-webui
(pip)
May 11, 2026
Open WebUI's chat completion API allows tool restrictions to be bypassed
High
CVE-2026-45350
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption
High
CVE-2026-45399
was published
for
open-webui
(pip)
May 14, 2026
wger: cross-tenant account deletion / deactivation / activation by gym.manage_gym + gym=None
High
GHSA-mw8f-w6p8-xrf4
was published
for
wger
(pip)
May 20, 2026
PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
High
CVE-2026-47394
was published
for
PraisonAI
(pip)
May 29, 2026
PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API
High
CVE-2026-48169
was published
for
praisonai-platform
(pip)
May 29, 2026
PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership
High
CVE-2026-47405
was published
for
praisonai-platform
(pip)
May 29, 2026
ProTip!
Advisories are also available from the
GraphQL API