GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,123
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
10,919 advisories
Filter by severity
HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to...
Low
Unreviewed
CVE-2026-56584
was published
Jul 21, 2026
OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the...
Moderate
Unreviewed
CVE-2026-65009
was published
Jul 21, 2026
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
High
GHSA-gcfj-64vw-6mp9
was published
for
axios
(npm)
Jul 20, 2026
File Browser: Share API exposes the password hash and bypass token
Low
CVE-2026-62684
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
Moderate
CVE-2026-59883
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
Guzzle: Proxy-Authorization headers can be sent to origin servers
Moderate
GHSA-94pj-82f3-465w
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw...
Moderate
Unreviewed
CVE-2026-60031
was published
Jul 20, 2026
An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the...
Critical
Unreviewed
CVE-2026-51027
was published
Jul 20, 2026
SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph...
High
Unreviewed
CVE-2026-63746
was published
Jul 20, 2026
The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user...
Moderate
Unreviewed
CVE-2026-8825
was published
Jul 20, 2026
A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get...
Moderate
Unreviewed
CVE-2026-16201
was published
Jul 19, 2026
An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source...
High
Unreviewed
CVE-2026-52203
was published
Jul 17, 2026
Prompty: Arbitrary file read via file reference expansion
High
CVE-2026-53598
was published
for
@prompty/core
(npm)
Jul 17, 2026
The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that...
Moderate
Unreviewed
CVE-2026-58149
was published
Jul 17, 2026
HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack...
Moderate
Unreviewed
CVE-2024-23570
was published
Jul 17, 2026
HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the...
Moderate
Unreviewed
CVE-2024-23568
was published
Jul 17, 2026
The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-9656
was published
Jul 17, 2026
The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status...
Moderate
Unreviewed
CVE-2026-13402
was published
Jul 17, 2026
The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Moderate
Unreviewed
CVE-2026-14503
was published
Jul 17, 2026
An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote...
Moderate
Unreviewed
CVE-2024-32385
was published
Jul 16, 2026
An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote...
Moderate
Unreviewed
CVE-2024-32387
was published
Jul 16, 2026
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
High
GHSA-x8mg-6r4p-87pf
was published
for
com.arcadedb:arcadedb-server
(Maven)
Jul 16, 2026
HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application...
Moderate
Unreviewed
CVE-2026-56456
was published
Jul 16, 2026
HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability....
Low
Unreviewed
CVE-2026-35145
was published
Jul 16, 2026
HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails...
Low
Unreviewed
CVE-2026-35143
was published
Jul 16, 2026
ProTip!
Advisories are also available from the
GraphQL API