GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,967
Maven
5,000+
npm
5,000+
NuGet
973
pip
5,000+
Pub
13
RubyGems
1,064
Rust
1,387
Swift
56
Unreviewed advisories
All unreviewed
5,000+
102 advisories
Filter by severity
Insufficient policy enforcement in Navigation in Google Chrome on Android prior to 149.0.7827.53...
Moderate
Unreviewed
CVE-2026-11287
was published
Jun 5, 2026
Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an...
Moderate
Unreviewed
CVE-2026-11267
was published
Jun 5, 2026
Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed...
High
Unreviewed
CVE-2026-11236
was published
Jun 5, 2026
Insufficient policy enforcement in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote...
Moderate
Unreviewed
CVE-2026-11184
was published
Jun 5, 2026
Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.53 allowed an...
High
Unreviewed
CVE-2026-11092
was published
Jun 5, 2026
Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an...
Moderate
Unreviewed
CVE-2026-11062
was published
Jun 5, 2026
Open WebUI has Improper Authorization Control
High
CVE-2026-44567
was published
for
open-webui
(pip)
May 8, 2026
JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request
High
CVE-2026-42266
was published
for
jupyterlab
(pip)
May 5, 2026
Insufficient policy enforcement in DevTools in Google Chrome prior to 147.0.7727.55 allowed an...
Moderate
Unreviewed
CVE-2026-5901
was published
Apr 9, 2026
A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to...
Moderate
Unreviewed
CVE-2026-30522
was published
Apr 1, 2026
A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to...
Moderate
Unreviewed
CVE-2026-30521
was published
Mar 31, 2026
Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a...
Moderate
Unreviewed
CVE-2026-3941
was published
Mar 12, 2026
FileBrowser Quantum: Password-Protected Share Bypass via /public/api/share/info
High
CVE-2026-30933
was published
for
github.com/gtsteffaniak/filebrowser/backend
(Go)
Mar 9, 2026
A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS,...
High
Unreviewed
CVE-2026-30783
was published
Mar 5, 2026
FileBrowser Quantum: Password Protection Not Enforced on Shared File Links
High
CVE-2026-27611
was published
for
github.com/gtsteffaniak/filebrowser/backend
(Go)
Feb 25, 2026
Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Client-Side Enforcement of...
Low
Unreviewed
CVE-2026-23859
was published
Feb 24, 2026
IBM ApplinX 11.1 could allow an authenticated user to perform unauthorized administrative actions...
Low
Unreviewed
CVE-2025-36410
was published
Jan 20, 2026
The Spin Wheel plugin for WordPress is vulnerable to client-side prize manipulation in all...
Moderate
Unreviewed
CVE-2026-0808
was published
Jan 17, 2026
IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an authenticated user to perform...
Moderate
Unreviewed
CVE-2025-14687
was published
Dec 26, 2025
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could...
Low
Unreviewed
CVE-2025-36102
was published
Dec 9, 2025
1Panel – CAPTCHA Bypass via Client-Controlled Flag
High
CVE-2025-66507
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 8, 2025
mJobtime 15.7.2 handles authorization on the client side, which allows an attacker to modify the...
Critical
Unreviewed
CVE-2025-51682
was published
Dec 1, 2025
The SKT PayPal for WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all...
High
Unreviewed
CVE-2025-7820
was published
Nov 27, 2025
The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2025-12788
was published
Nov 11, 2025
A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an...
High
Unreviewed
CVE-2025-10622
was published
Nov 5, 2025
ProTip!
Advisories are also available from the
GraphQL API