GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
2,418 advisories
Filter by severity
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain...
High
Unreviewed
CVE-2026-93678
was published
Oct 7, 2026
Authorization bypass through a user-controlled key in the optional Amazon Q Business Lambda hook...
High
Unreviewed
CVE-2026-105811
was published
Oct 6, 2026
Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to...
High
Unreviewed
CVE-2026-103009
was published
Oct 6, 2026
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant...
High
Unreviewed
CVE-2026-102406
was published
Oct 6, 2026
An insecure direct object reference (IDOR) vulnerability in a CloudVision CUE file-serving...
Moderate
Unreviewed
CVE-2026-102157
was published
Oct 6, 2026
Payload: Polymorphic join queries could disclose hidden fields
High
CVE-2026-105847
was published
for
payload
(npm)
Oct 6, 2026
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18.
...
Moderate
Unreviewed
CVE-2026-87975
was published
Oct 6, 2026
QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminProductsController:...
Moderate
Unreviewed
CVE-2026-105836
was published
Oct 6, 2026
Unauthenticated Insecure Direct Object References (IDOR) in Wappointment <= 2.7.7 versions.
Moderate
Unreviewed
CVE-2026-39756
was published
Oct 6, 2026
Customer Insecure Direct Object References (IDOR) in Faktur Pro for WooCommerce <= 3.2.1 versions.
Moderate
Unreviewed
CVE-2026-32576
was published
Oct 6, 2026
openSIS Classic 9.3 allows an authenticated user with the built-in teacher role can select an...
Critical
Unreviewed
CVE-2026-91107
was published
Oct 6, 2026
vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features
Moderate
CVE-2026-105754
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`
Moderate
CVE-2026-105755
was published
for
vllm
(pip)
Oct 5, 2026
Authorization Bypass Through User-Controlled Key vulnerability in Themeisle AI Chatbot for...
Moderate
Unreviewed
CVE-2026-97305
was published
Oct 5, 2026
Authorization Bypass Through User-Controlled Key vulnerability in CozyThemes Cozy Blocks cozy...
Moderate
Unreviewed
CVE-2026-97070
was published
Oct 5, 2026
Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be...
Moderate
Unreviewed
CVE-2026-78412
was published
Oct 5, 2026
Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in Order...
High
Unreviewed
CVE-2026-102775
was published
Oct 5, 2026
Authorization Bypass Through User-Controlled Key vulnerability in Ahmad JS Help Desk js-support...
Moderate
Unreviewed
CVE-2026-103078
was published
Oct 5, 2026
Authorization Bypass Through User-Controlled Key vulnerability in Ahmad JS Help Desk js-support...
Moderate
Unreviewed
CVE-2026-103079
was published
Oct 5, 2026
The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the...
Moderate
Unreviewed
CVE-2026-78371
was published
Oct 5, 2026
The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment...
Moderate
Unreviewed
CVE-2026-84169
was published
Oct 5, 2026
The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or...
Moderate
Unreviewed
CVE-2026-104118
was published
Oct 4, 2026
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member...
High
Unreviewed
CVE-2026-96451
was published
Oct 3, 2026
The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure...
Moderate
Unreviewed
CVE-2026-11399
was published
Oct 3, 2026
UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference...
Moderate
Unreviewed
CVE-2026-105029
was published
Oct 3, 2026
ProTip!
Advisories are also available from the
GraphQL API