GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,739
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
8,990 advisories
Filter by severity
The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all...
Moderate
Unreviewed
CVE-2024-12145
was published
Sep 11, 2026
The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests...
Low
Unreviewed
CVE-2026-86779
was published
Sep 11, 2026
The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its...
Moderate
Unreviewed
CVE-2026-86815
was published
Sep 11, 2026
The Woo PDF Invoice Builder plugin (also distributed as "PDF Builder for WooCommerce") for...
Moderate
Unreviewed
CVE-2026-11496
was published
Sep 11, 2026
The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-11446
was published
Sep 11, 2026
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute...
High
Unreviewed
CVE-2026-81211
was published
Sep 11, 2026
A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without...
High
Unreviewed
CVE-2026-89054
was published
Sep 10, 2026
n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
Moderate
CVE-2026-86085
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
Moderate
CVE-2026-86993
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
Moderate
CVE-2026-86994
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
Moderate
CVE-2026-86077
was published
for
n8n
(npm)
Sep 10, 2026
Anchor CMS through 0.12.7 fails to enforce role-based access control in admin user-management...
High
Unreviewed
CVE-2026-88959
was published
Sep 10, 2026
There is an improper access control vulnerability in NI SystemLink that may allow an...
High
Unreviewed
CVE-2026-4129
was published
Sep 10, 2026
Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.
High
Unreviewed
CVE-2026-81801
was published
Sep 10, 2026
AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in...
High
Unreviewed
CVE-2026-88898
was published
Sep 10, 2026
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.
High
Unreviewed
CVE-2026-84821
was published
Sep 10, 2026
Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4...
High
Unreviewed
CVE-2026-81799
was published
Sep 10, 2026
Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.
High
Unreviewed
CVE-2026-81794
was published
Sep 10, 2026
Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.
Moderate
Unreviewed
CVE-2026-81788
was published
Sep 10, 2026
Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2...
High
Unreviewed
CVE-2026-81786
was published
Sep 10, 2026
Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions.
Moderate
Unreviewed
CVE-2026-81785
was published
Sep 10, 2026
Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9...
Moderate
Unreviewed
CVE-2026-78536
was published
Sep 10, 2026
Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.
Moderate
Unreviewed
CVE-2026-81793
was published
Sep 10, 2026
Affected versions of MISP do not consistently enforce the acting user's authorization when...
High
Unreviewed
CVE-2026-88915
was published
Sep 10, 2026
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
Moderate
CVE-2026-87994
was published
for
open-webui
(pip)
Sep 10, 2026
ProTip!
Advisories are also available from the
GraphQL API