GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,248
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,513
Pub
12
RubyGems
997
Rust
1,189
Swift
51
Unreviewed advisories
All unreviewed
5,000+
6,660 advisories
Filter by severity
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor...
High
Unreviewed
CVE-2024-0324
was published
Feb 6, 2024
Azure Blob Storage for Craft CMS Potential Sensitive Information Disclosure vulnerability
High
CVE-2026-32268
was published
for
craftcms/azure-blob
(Composer)
Mar 16, 2026
Yoast Duplicate Post has an Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite
Moderate
CVE-2026-1217
was published
for
yoast/duplicate-post
(Composer)
Mar 18, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories
High
CVE-2026-33353
was published
for
github.com/charmbracelet/soft-serve
(Go)
Mar 19, 2026
Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to...
Moderate
Unreviewed
CVE-2026-26939
was published
Mar 19, 2026
Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access...
High
Unreviewed
CVE-2026-25312
was published
Mar 19, 2026
Missing Authorization vulnerability in Dotstore Fraud Prevention For Woocommerce allows...
High
Unreviewed
CVE-2026-25443
was published
Mar 19, 2026
The Instant Popup Builder plugin for WordPress is vulnerable to Unauthenticated Arbitrary...
Moderate
Unreviewed
CVE-2026-3475
was published
Mar 19, 2026
Missing Authorization vulnerability in UiPress UiPress lite allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2026-27091
was published
Mar 19, 2026
Missing Authorization vulnerability in Tips and Tricks HQ WP eMember allows Exploiting...
Moderate
Unreviewed
CVE-2026-28070
was published
Mar 19, 2026
Admidio is Missing Authorization on Forum Topic and Post Deletion
Moderate
CVE-2026-32818
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Admidio is Missing Authorization and CSRF Protection on Document and Folder Deletion
Critical
CVE-2026-32817
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Statamic is missing authorization check on taxonomy term creation via fieldtype
Moderate
CVE-2026-33177
was published
for
statamic/cms
(Composer)
Mar 18, 2026
The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a...
Moderate
Unreviewed
CVE-2026-2559
was published
Mar 18, 2026
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2026-2992
was published
Mar 18, 2026
Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization
High
CVE-2026-30911
was published
for
apache-airflow
(pip)
Mar 17, 2026
Missing Authorization vulnerability in WebberZone Contextual Related Posts allows Exploiting...
Moderate
Unreviewed
CVE-2026-32565
was published
Mar 18, 2026
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification...
Moderate
Unreviewed
CVE-2026-1926
was published
Mar 18, 2026
The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress...
Moderate
Unreviewed
CVE-2024-0371
was published
Feb 6, 2024
The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress...
Moderate
Unreviewed
CVE-2024-0372
was published
Feb 6, 2024
Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before...
High
Unreviewed
CVE-2026-4064
was published
Mar 17, 2026
wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows...
High
Unreviewed
CVE-2026-22182
was published
Mar 13, 2026
Mattermost fails to filter invite IDs based on user permissions
Moderate
CVE-2026-2463
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Mattermost allows a removed team member to enumerate all public channels within a private team
Moderate
CVE-2026-2458
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Missing Authorization vulnerability in Pluggabl Booster for WooCommerce allows Exploiting...
Moderate
Unreviewed
CVE-2026-32586
was published
Mar 17, 2026
ProTip!
Advisories are also available from the
GraphQL API