GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
203 advisories
Filter by severity
Capgo before 12.128.2 allows email address changes without requiring current password re...
High
Unreviewed
CVE-2026-56308
was published
Jul 12, 2026
A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function...
Moderate
Unreviewed
CVE-2026-15479
was published
Jul 12, 2026
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress...
High
Unreviewed
CVE-2026-15155
was published
Jul 11, 2026
The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in...
High
Unreviewed
CVE-2026-7655
was published
Jul 11, 2026
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing...
Critical
Unreviewed
CVE-2026-13019
was published
Jul 7, 2026
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS...
High
Unreviewed
CVE-2026-13020
was published
Jul 7, 2026
An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2026-37106
was published
Jul 1, 2026
The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password...
Critical
Unreviewed
CVE-2026-12417
was published
Jun 24, 2026
The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset...
Critical
Unreviewed
CVE-2026-12416
was published
Jun 24, 2026
Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and...
Critical
Unreviewed
CVE-2026-56081
was published
Jun 20, 2026
The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all...
Critical
Unreviewed
CVE-2026-11551
was published
Jun 20, 2026
A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the...
Moderate
Unreviewed
CVE-2026-12066
was published
Jun 12, 2026
LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header...
High
Unreviewed
CVE-2026-50635
was published
Jun 9, 2026
A vulnerability was detected in OUSL-GROUP-BrinaryBrains School Student Management System up to...
Low
Unreviewed
CVE-2026-10169
was published
May 31, 2026
The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable...
High
Unreviewed
CVE-2026-7459
was published
May 30, 2026
A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of...
Low
Unreviewed
CVE-2026-9609
was published
May 27, 2026
A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7.17.0. This issue...
Moderate
Unreviewed
CVE-2026-9466
was published
May 26, 2026
An issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain...
Moderate
Unreviewed
CVE-2026-36438
was published
May 18, 2026
The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Password Recovery...
Moderate
Unreviewed
CVE-2026-7652
was published
May 9, 2026
An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0...
Critical
Unreviewed
CVE-2026-34408
was published
May 5, 2026
A vulnerability was determined in D-Link M60 up to 1.20B02. Affected by this issue is some...
Low
Unreviewed
CVE-2026-7554
was published
May 1, 2026
Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An...
Moderate
Unreviewed
CVE-2025-36579
was published
Apr 16, 2026
An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated...
High
Unreviewed
CVE-2026-30459
was published
Apr 16, 2026
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated...
Moderate
Unreviewed
CVE-2026-4136
was published
Mar 20, 2026
Incorrect Access Control via activation token reuse on the password-reset endpoint allowing...
Critical
Unreviewed
CVE-2025-69614
was published
Mar 10, 2026
ProTip!
Advisories are also available from the
GraphQL API