GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
1,752 advisories
Filter by severity
Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0...
Moderate
Unreviewed
CVE-2026-65501
was published
Jul 23, 2026
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
Moderate
Unreviewed
CVE-2026-65463
was published
Jul 23, 2026
Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62...
Moderate
Unreviewed
CVE-2026-65456
was published
Jul 23, 2026
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
Moderate
Unreviewed
CVE-2026-61946
was published
Jul 23, 2026
n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
Moderate
CVE-2026-59253
was published
for
n8n
(npm)
Jul 22, 2026
n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
Moderate
CVE-2026-59254
was published
for
n8n
(npm)
Jul 22, 2026
n8n: External Secrets Permission Bypass via Expression Parser Mismatch
Moderate
CVE-2026-59259
was published
for
n8n
(npm)
Jul 22, 2026
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
High
CVE-2026-65016
was published
for
n8n
(npm)
Jul 22, 2026
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0...
Moderate
Unreviewed
CVE-2026-3482
was published
Jul 22, 2026
Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization...
High
Unreviewed
CVE-2026-65013
was published
Jul 22, 2026
Duplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
High
GHSA-mwq7-vcmc-cm4q
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
Authorization bypass through User-Controlled key vulnerability in Universe Software Computer...
Moderate
Unreviewed
CVE-2026-2406
was published
Jul 22, 2026
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information...
Moderate
Unreviewed
CVE-2026-63259
was published
Jul 22, 2026
XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows...
High
Unreviewed
CVE-2026-65316
was published
Jul 22, 2026
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized...
High
Unreviewed
CVE-2026-56147
was published
Jul 21, 2026
Gitea LFS Deploy-Key Privilege Escalation
Moderate
CVE-2026-58435
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
Low
CVE-2026-58445
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
High
CVE-2026-28740
was published
for
gitea.dev
(Go)
Jul 21, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
Moderate
CVE-2026-57886
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: draft release attachment disclosure via missing web authorization
Moderate
CVE-2026-58432
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to...
Critical
Unreviewed
CVE-2026-28314
was published
Jul 21, 2026
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that...
Critical
Unreviewed
CVE-2026-28313
was published
Jul 21, 2026
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that...
Critical
Unreviewed
CVE-2026-28316
was published
Jul 21, 2026
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that...
Critical
Unreviewed
CVE-2026-28317
was published
Jul 21, 2026
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that...
Critical
Unreviewed
CVE-2026-28302
was published
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API