GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
150,381 advisories
Filter by severity
Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.
Moderate
Unreviewed
CVE-2026-65473
was published
Jul 23, 2026
Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.
Moderate
Unreviewed
CVE-2026-65476
was published
Jul 23, 2026
Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.
Moderate
Unreviewed
CVE-2026-65478
was published
Jul 23, 2026
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
Moderate
Unreviewed
CVE-2026-65474
was published
Jul 23, 2026
Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
Moderate
Unreviewed
CVE-2026-65482
was published
Jul 23, 2026
Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
Moderate
Unreviewed
CVE-2026-65457
was published
Jul 23, 2026
Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62...
Moderate
Unreviewed
CVE-2026-65456
was published
Jul 23, 2026
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
Moderate
Unreviewed
CVE-2026-65453
was published
Jul 23, 2026
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
Moderate
Unreviewed
CVE-2026-65452
was published
Jul 23, 2026
Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions.
Moderate
Unreviewed
CVE-2026-65458
was published
Jul 23, 2026
Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.
Moderate
Unreviewed
CVE-2026-65460
was published
Jul 23, 2026
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
Moderate
Unreviewed
CVE-2026-61946
was published
Jul 23, 2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
Moderate
Unreviewed
CVE-2026-61945
was published
Jul 23, 2026
Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
Moderate
Unreviewed
CVE-2026-61972
was published
Jul 23, 2026
Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
Moderate
Unreviewed
CVE-2026-61973
was published
Jul 23, 2026
Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.
Moderate
Unreviewed
CVE-2026-61981
was published
Jul 23, 2026
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification,...
Moderate
Unreviewed
CVE-2026-64810
was published
Jul 23, 2026
Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.
Moderate
Unreviewed
CVE-2026-65449
was published
Jul 23, 2026
Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.
Moderate
Unreviewed
CVE-2026-57808
was published
Jul 23, 2026
Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.
Moderate
Unreviewed
CVE-2026-57703
was published
Jul 23, 2026
Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.
Moderate
Unreviewed
CVE-2026-57717
was published
Jul 23, 2026
Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.
Moderate
Unreviewed
CVE-2026-57716
was published
Jul 23, 2026
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
Moderate
Unreviewed
CVE-2026-59522
was published
Jul 23, 2026
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
Moderate
Unreviewed
CVE-2026-59524
was published
Jul 23, 2026
Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.
Moderate
Unreviewed
CVE-2026-59513
was published
Jul 23, 2026
ProTip!
Advisories are also available from the
GraphQL API