GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
7,028 advisories
Filter by severity
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a...
Moderate
Unreviewed
CVE-2026-11549
was published
Sep 18, 2026
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
High
CVE-2026-58197
was published
for
github.com/stacklok/toolhive
(Go)
Sep 18, 2026
vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an...
Moderate
Unreviewed
CVE-2026-93604
was published
Sep 18, 2026
HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which...
Moderate
Unreviewed
CVE-2026-21848
was published
Sep 18, 2026
The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled...
Moderate
Unreviewed
CVE-2026-90976
was published
Sep 18, 2026
The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to...
Moderate
Unreviewed
CVE-2026-87965
was published
Sep 18, 2026
The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX...
High
Unreviewed
CVE-2026-90978
was published
Sep 18, 2026
The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted...
Moderate
Unreviewed
CVE-2026-85123
was published
Sep 18, 2026
A vulnerability in the team folders (formerly group folders) app when used in combination with...
Moderate
Unreviewed
CVE-2026-77169
was published
Sep 18, 2026
The Deck config API allows authenticated users to set board-scoped configuration keys for...
Moderate
Unreviewed
CVE-2026-77170
was published
Sep 18, 2026
The Photos app's filter-based "smart albums" build their file listing using the search...
Moderate
Unreviewed
CVE-2026-82985
was published
Sep 18, 2026
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges...
Critical
Unreviewed
CVE-2026-83944
was published
Sep 18, 2026
MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests
Low
CVE-2026-61700
was published
for
org.mariadb.jdbc:mariadb-java-client
(Maven)
Sep 17, 2026
A vulnerability has been identified in the Acer System Monitoring component included with...
High
Unreviewed
CVE-2026-50609
was published
Sep 17, 2026
A vulnerability has been identified in the Acer System Monitoring component included with...
High
Unreviewed
CVE-2026-50610
was published
Sep 17, 2026
A vulnerability has been identified in the Acer Agent Service component included with NitroSense...
High
Unreviewed
CVE-2026-50605
was published
Sep 17, 2026
The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who...
Moderate
Unreviewed
CVE-2026-91019
was published
Sep 17, 2026
The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount...
Moderate
Unreviewed
CVE-2026-90922
was published
Sep 17, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure...
Critical
Unreviewed
CVE-2026-20332
was published
Sep 16, 2026
A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of...
Moderate
Unreviewed
CVE-2026-20121
was published
Sep 16, 2026
A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of...
Moderate
Unreviewed
CVE-2026-20120
was published
Sep 16, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus...
Critical
Unreviewed
CVE-2026-20322
was published
Sep 16, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco...
Critical
Unreviewed
CVE-2026-20192
was published
Sep 16, 2026
The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board...
Low
Unreviewed
CVE-2026-89328
was published
Sep 16, 2026
The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action...
Moderate
Unreviewed
CVE-2026-87959
was published
Sep 16, 2026
ProTip!
Advisories are also available from the
GraphQL API