GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
1,770 advisories
Filter by severity
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console...
Critical
Unreviewed
CVE-2026-66013
was published
Jul 25, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
Moderate
GHSA-86cx-wwf4-phq4
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
Moderate
GHSA-p6ph-3jx2-3337
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
High
GHSA-rm67-g9ch-vxff
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
Critical
GHSA-p279-2cqp-84jg
was published
for
org.openidentityplatform.opendj:opendj-server-legacy
(Maven)
Jul 24, 2026
Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
High
GHSA-c8vc-7pv3-g98p
was published
for
@budibase/server
(npm)
Jul 24, 2026
sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the...
High
Unreviewed
CVE-2026-65709
was published
Jul 24, 2026
sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that...
High
Unreviewed
CVE-2026-65708
was published
Jul 24, 2026
sysPass through version 3.2.11 contains a missing authorization vulnerability that allows...
High
Unreviewed
CVE-2026-65710
was published
Jul 24, 2026
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
Low
CVE-2026-59215
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
High
CVE-2026-59216
was published
for
open-webui
(pip)
Jul 24, 2026
@better-auth/stripe: cross-organization billing tampering in organization subscription actions
High
GHSA-h3rm-78g3-j7cp
was published
for
@better-auth/stripe
(npm)
Jul 24, 2026
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
Critical
GHSA-rjg6-39jm-rgg4
was published
for
@better-auth/scim
(npm)
Jul 24, 2026
A flaw was found in the role-users endpoint of the keycloak-services library, which is the core...
Moderate
Unreviewed
CVE-2026-17059
was published
Jul 24, 2026
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-13464
was published
Jul 24, 2026
AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability...
Low
Unreviewed
CVE-2026-65699
was published
Jul 23, 2026
Overseerr through 1.35.0 contains an authorization bypass through user-controlled key...
Moderate
Unreviewed
CVE-2026-65696
was published
Jul 23, 2026
CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference ...
High
Unreviewed
CVE-2026-65917
was published
Jul 23, 2026
Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0...
Moderate
Unreviewed
CVE-2026-65501
was published
Jul 23, 2026
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
Moderate
Unreviewed
CVE-2026-65463
was published
Jul 23, 2026
Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62...
Moderate
Unreviewed
CVE-2026-65456
was published
Jul 23, 2026
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
Moderate
Unreviewed
CVE-2026-61946
was published
Jul 23, 2026
n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
Moderate
CVE-2026-59253
was published
for
n8n
(npm)
Jul 22, 2026
n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
Moderate
CVE-2026-59254
was published
for
n8n
(npm)
Jul 22, 2026
n8n: External Secrets Permission Bypass via Expression Parser Mismatch
Moderate
CVE-2026-59259
was published
for
n8n
(npm)
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API