GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
4,472 advisories
Filter by severity
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with...
High
Unreviewed
CVE-2026-67356
was published
Aug 2, 2026
The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to...
High
Unreviewed
CVE-2026-16635
was published
Aug 1, 2026
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in...
High
Unreviewed
CVE-2026-15414
was published
Aug 1, 2026
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)
Moderate
CVE-2026-65835
was published
for
github.com/projectcapsule/capsule
(Go)
Jul 31, 2026
The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level...
High
Unreviewed
CVE-2026-12251
was published
Jul 31, 2026
The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly...
High
Unreviewed
CVE-2026-14333
was published
Jul 31, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site...
High
Unreviewed
CVE-2026-14980
was published
Jul 30, 2026
The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous...
High
Unreviewed
CVE-2026-12687
was published
Jul 30, 2026
Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a...
High
Unreviewed
CVE-2026-17969
was published
Jul 30, 2026
Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72...
High
Unreviewed
CVE-2026-17950
was published
Jul 30, 2026
Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker...
High
Unreviewed
CVE-2026-17952
was published
Jul 30, 2026
Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a...
High
Unreviewed
CVE-2026-17956
was published
Jul 30, 2026
Inappropriate implementation in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a...
High
Unreviewed
CVE-2026-17864
was published
Jul 30, 2026
Inappropriate implementation in Browser in Google Chrome on Windows prior to 151.0.7922.72...
High
Unreviewed
CVE-2026-17863
was published
Jul 30, 2026
Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote...
High
Unreviewed
CVE-2026-17868
was published
Jul 30, 2026
Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72...
High
Unreviewed
CVE-2026-17877
was published
Jul 30, 2026
Insufficient policy enforcement in Speech in Google Chrome on Android prior to 151.0.7922.72...
High
Unreviewed
CVE-2026-17816
was published
Jul 30, 2026
Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote...
High
Unreviewed
CVE-2026-17751
was published
Jul 30, 2026
Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72...
High
Unreviewed
CVE-2026-17744
was published
Jul 30, 2026
The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all...
High
Unreviewed
CVE-2026-12144
was published
Jul 29, 2026
A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A...
High
Unreviewed
CVE-2026-18107
was published
Jul 28, 2026
The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions...
High
Unreviewed
CVE-2026-15992
was published
Jul 28, 2026
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption
High
CVE-2026-50570
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress...
High
Unreviewed
CVE-2026-14328
was published
Jul 28, 2026
The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting...
Critical
Unreviewed
CVE-2026-14545
was published
Jul 28, 2026
ProTip!
Advisories are also available from the
GraphQL API