GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
375,289 advisories
Filter by severity
The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it...
Moderate
Unreviewed
CVE-2026-87068
was published
Sep 20, 2026
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be...
High
Unreviewed
CVE-2026-87067
was published
Sep 20, 2026
The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before...
Low
Unreviewed
CVE-2026-92965
was published
Sep 20, 2026
The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability...
High
Unreviewed
CVE-2026-85017
was published
Sep 20, 2026
The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them...
Moderate
Unreviewed
CVE-2026-84223
was published
Sep 20, 2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the...
Low
Unreviewed
CVE-2026-81652
was published
Sep 20, 2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the...
Low
Unreviewed
CVE-2026-81651
was published
Sep 20, 2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly...
High
Unreviewed
CVE-2026-81650
was published
Sep 20, 2026
A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown part...
Low
Unreviewed
CVE-2026-94032
was published
Sep 20, 2026
A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914....
Low
Unreviewed
CVE-2026-94031
was published
Sep 20, 2026
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects...
Low
Unreviewed
CVE-2026-94034
was published
Sep 20, 2026
A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function...
Low
Unreviewed
CVE-2026-94028
was published
Sep 20, 2026
A security vulnerability has been detected in SerenityOS up to...
Low
Unreviewed
CVE-2026-94030
was published
Sep 20, 2026
A vulnerability has been found in SourceCodester Drug Recommendation System 1.0. This...
Low
Unreviewed
CVE-2026-94033
was published
Sep 20, 2026
Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog...
Moderate
Unreviewed
CVE-2026-92254
was published
Sep 20, 2026
An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough...
Critical
Unreviewed
CVE-2026-90817
was published
Sep 20, 2026
Incorrect default permissions in the installation directory of WatchDog Anti-Virus on Windows...
Moderate
Unreviewed
CVE-2026-92252
was published
Sep 20, 2026
Improper link resolution before file access in the quarantine restoration process of WatchDog...
Moderate
Unreviewed
CVE-2026-92253
was published
Sep 20, 2026
A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an...
Moderate
Unreviewed
CVE-2026-94015
was published
Sep 20, 2026
A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This...
Low
Unreviewed
CVE-2026-94016
was published
Sep 20, 2026
The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or...
Low
Unreviewed
CVE-2026-92423
was published
Sep 20, 2026
The Import and export users and customers WordPress plugin before 2.5.2 does not correctly...
High
Unreviewed
CVE-2026-92540
was published
Sep 20, 2026
The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the...
High
Unreviewed
CVE-2026-92541
was published
Sep 20, 2026
The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on...
Moderate
Unreviewed
CVE-2026-87840
was published
Sep 20, 2026
The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not...
High
Unreviewed
CVE-2026-87839
was published
Sep 20, 2026
ProTip!
Advisories are also available from the
GraphQL API