GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
183 advisories
Filter by severity
A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an...
Moderate
Unreviewed
CVE-2026-78051
was published
Aug 23, 2026
A low-privileged remote attacker can enumerate all configured users and identify which accounts...
Moderate
Unreviewed
CVE-2026-14953
was published
Aug 20, 2026
A weakness has been identified in code-projects Login Registration System 1.0. This affects an...
Moderate
Unreviewed
CVE-2026-76799
was published
Aug 20, 2026
A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an...
Moderate
Unreviewed
CVE-2026-19903
was published
Aug 15, 2026
Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to...
Moderate
Unreviewed
CVE-2026-60011
was published
Aug 3, 2026
HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing)...
Moderate
Unreviewed
CVE-2026-21760
was published
Jul 17, 2026
HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that...
Low
Unreviewed
CVE-2024-23573
was published
Jul 17, 2026
A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this...
Moderate
Unreviewed
CVE-2026-13533
was published
Jun 29, 2026
An high privileged remote attacker can access a hidden configuration method, that should not be...
High
Unreviewed
CVE-2026-10521
was published
Jun 23, 2026
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes...
Low
Unreviewed
CVE-2026-9610
was published
Jun 22, 2026
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, exposes web-accessible...
Moderate
Unreviewed
CVE-2026-34028
was published
Jun 15, 2026
Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks
Moderate
CVE-2026-11986
was published
for
org.keycloak:keycloak-rest-admin-ui-ext
(Maven)
Jun 11, 2026
Concrete CMS is vulnerable to authorization bypass in the Calendar Block
Moderate
CVE-2026-8205
was published
for
concrete5/concrete5
(Composer)
May 21, 2026
Keycloak has a Forced Browsing issue
Moderate
CVE-2026-7500
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 30, 2026
Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via...
Moderate
Unreviewed
CVE-2024-58343
was published
Apr 17, 2026
A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an...
Moderate
Unreviewed
CVE-2026-4900
was published
Mar 27, 2026
A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0...
Moderate
Unreviewed
CVE-2026-4532
was published
Mar 22, 2026
Spring Security HTTP Headers Are not Written Under Some Conditions
Critical
CVE-2026-22732
was published
for
org.springframework.security:spring-security-web
(Maven)
Mar 20, 2026
OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess...
Moderate
Unreviewed
CVE-2026-32867
was published
Mar 19, 2026
Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 allow a low privileged...
High
Unreviewed
CVE-2025-15587
was published
Mar 16, 2026
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
High
Unreviewed
CVE-2026-25679
was published
Mar 7, 2026
A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some...
Moderate
Unreviewed
CVE-2026-1978
was published
Feb 6, 2026
ALGO 8180 IP Audio Alerter Web UI Direct Request Information Disclosure Vulnerability. This...
Moderate
Unreviewed
CVE-2026-0790
was published
Jan 23, 2026
OpenFlagr contains an authentication bypass vulnerability in the HTTP middleware
Critical
CVE-2026-0650
was published
for
github.com/openflagr/flagr
(Go)
Jan 7, 2026
A weakness has been identified in PbootCMS up to 3.2.12. Impacted is an unknown function of the...
Moderate
Unreviewed
CVE-2025-15153
was published
Dec 28, 2025
ProTip!
Advisories are also available from the
GraphQL API