GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
4,627 advisories
Filter by severity
The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform proper authorization...
Moderate
Unreviewed
CVE-2026-105976
was published
Oct 10, 2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for...
Moderate
Unreviewed
CVE-2026-6723
was published
Oct 10, 2026
Vikunja: Write-level project members can delete admin-tier link shares through an unloaded permission check
Moderate
GHSA-fmmf-xq98-g327
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Webhooks and link shares survive every revocation path, so a removed collaborator keeps a live feed
Moderate
GHSA-hjx8-qv73-f7cm
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Saved filter creation with an empty filter string recalculates task positions across all tenants
Moderate
GHSA-fprf-r6rv-xg99
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Contao: Improper access control in the table access voter
Moderate
CVE-2026-107851
was published
for
contao/core-bundle
(Composer)
Oct 9, 2026
Vikunja: Link-share token can enumerate users through the v2 API
Moderate
CVE-2026-91981
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: API token scopes bypassed via task expand parameter (comments, reactions, time entry counts)
Moderate
CVE-2026-91983
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Cross-tenant task-position rows can be injected into arbitrary project views via the unvalidated project_view_id in the task position endpoint (v1 and v2)
Moderate
CVE-2026-91984
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Link-share principal-type confusion enables cross-account team removal, bot takeover, and roster disclosure
High
CVE-2026-76216
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
pacioli: A submit consent marker licensed cancellation of caller-named pre-existing documents
Moderate
CVE-2026-107841
was published
for
pacioli-guard
(pip)
Oct 9, 2026
Vikunja: Link-share token reads any tenant's kanban buckets and enumerates usernames/IDs instance-wide (BOLA)
Critical
CVE-2026-68582
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Link-share principal ID collision allows cross-account API token issuance and management
High
CVE-2026-68581
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Strawberry GraphQL: Synchronous permission checks can treat an awaitable authorization result as truthy
High
CVE-2026-107728
was published
for
strawberry-graphql
(pip)
Oct 9, 2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an...
Moderate
Unreviewed
CVE-2026-78341
was published
Oct 9, 2026
PraisonAI: Platform member PATCH routes allow owner resource rewrites and project lead reassignment delete bypass
High
CVE-2026-61442
was published
for
praisonai-platform
(pip)
Oct 8, 2026
PraisonAI: Platform members can rewrite shared labels and owner issue labels without owner/admin authorization
Moderate
CVE-2026-61440
was published
for
praisonai-platform
(pip)
Oct 8, 2026
System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the...
High
Unreviewed
CVE-2026-107782
was published
Oct 8, 2026
Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core...
Moderate
Unreviewed
CVE-2026-107706
was published
Oct 8, 2026
In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted...
Moderate
Unreviewed
CVE-2026-93861
was published
Oct 8, 2026
In OpenStack Mistral through 23.0.0, several of the v2 API write paths resolve the target object...
High
Unreviewed
CVE-2026-97147
was published
Oct 8, 2026
Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its...
High
Unreviewed
CVE-2026-107333
was published
Oct 8, 2026
Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user...
Moderate
Unreviewed
CVE-2026-107334
was published
Oct 8, 2026
A policy-enforcement flaw in Zimbra Collaboration Suite allows an authenticated user to bypass...
Moderate
Unreviewed
CVE-2026-50055
was published
Oct 8, 2026
AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy logins
High
CVE-2026-107230
was published
for
org.asynchttpclient:async-http-client
(Maven)
Oct 8, 2026
ProTip!
Advisories are also available from the
GraphQL API