GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
736 advisories
Filter by severity
A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the...
Low
Unreviewed
CVE-2026-101278
was published
Sep 29, 2026
The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider...
Moderate
Unreviewed
CVE-2026-92996
was published
Sep 28, 2026
The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe...
Moderate
Unreviewed
CVE-2026-89411
was published
Sep 28, 2026
Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart...
High
Unreviewed
CVE-2026-100872
was published
Sep 27, 2026
FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider
Critical
CVE-2026-92161
was published
for
fof/oauth
(Composer)
Sep 25, 2026
The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware...
Critical
Unreviewed
CVE-2026-81630
was published
Sep 24, 2026
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature...
Moderate
Unreviewed
CVE-2026-87978
was published
Sep 23, 2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise...
Moderate
Unreviewed
CVE-2026-81338
was published
Sep 23, 2026
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code...
Critical
Unreviewed
CVE-2026-28324
was published
Sep 22, 2026
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that...
Moderate
Unreviewed
CVE-2026-92400
was published
Sep 21, 2026
The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value...
Moderate
Unreviewed
CVE-2026-92422
was published
Sep 20, 2026
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body
Moderate
CVE-2026-63405
was published
for
github.com/anycable/anycable
(Go)
Sep 18, 2026
Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker...
Critical
Unreviewed
CVE-2026-62874
was published
Sep 18, 2026
libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses
High
CVE-2026-86039
was published
for
@libp2p/peer-store
(npm)
Sep 17, 2026
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
High
CVE-2026-86038
was published
for
@libp2p/gossipsub
(npm)
Sep 17, 2026
Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data...
High
Unreviewed
CVE-2026-26950
was published
Sep 17, 2026
Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth...
Moderate
Unreviewed
CVE-2026-78296
was published
Sep 17, 2026
The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the...
Low
Unreviewed
CVE-2026-91017
was published
Sep 17, 2026
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
High
CVE-2026-63127
was published
for
rmcp
(Rust)
Sep 16, 2026
djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
High
CVE-2026-61591
was published
for
djust
(pip)
Sep 16, 2026
kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file...
Critical
Unreviewed
CVE-2026-88592
was published
Sep 16, 2026
The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier...
Moderate
Unreviewed
CVE-2026-92138
was published
Sep 16, 2026
An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard...
Moderate
Unreviewed
CVE-2026-19941
was published
Sep 16, 2026
Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity...
High
Unreviewed
CVE-2026-73177
was published
Sep 16, 2026
A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function...
Moderate
Unreviewed
CVE-2026-92360
was published
Sep 16, 2026
ProTip!
Advisories are also available from the
GraphQL API