GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
43
Go
3,181
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,474
Pub
12
RubyGems
991
Rust
1,185
Swift
51
Unreviewed advisories
All unreviewed
5,000+
152,463 advisories
Filter by severity
Missing Authorization vulnerability in Pluggabl Booster for WooCommerce allows Exploiting...
Moderate
Unreviewed
CVE-2026-32586
was published
Mar 17, 2026
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-2373
was published
Mar 17, 2026
A security flaw has been discovered in frdel/agent0ai agent-zero 0.9.7-10. The impacted element...
Moderate
Unreviewed
CVE-2026-4307
was published
Mar 17, 2026
A weakness has been identified in frdel/agent0ai agent-zero 0.9.7. This affects the function...
Moderate
Unreviewed
CVE-2026-4308
was published
Mar 17, 2026
A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.
Moderate
Unreviewed
CVE-2026-21991
was published
Mar 17, 2026
A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7...
Moderate
Unreviewed
CVE-2026-4289
was published
Mar 17, 2026
A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. The...
Moderate
Unreviewed
CVE-2026-4287
was published
Mar 17, 2026
A vulnerability was identified in taoofagi easegen-admin up to...
Moderate
Unreviewed
CVE-2026-4285
was published
Mar 17, 2026
A weakness has been identified in Tiandy Easy7 Integrated Management Platform 7.17.0. The...
Moderate
Unreviewed
CVE-2026-4288
was published
Mar 17, 2026
A vulnerability was determined in taoofagi easegen-admin up to...
Moderate
Unreviewed
CVE-2026-4284
was published
Mar 17, 2026
Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The...
Moderate
Unreviewed
CVE-2025-69693
was published
Mar 16, 2026
Buffalo TeraStation NAS TS5400R firmware version 4.02-0.06 and prior contain an excessive file...
Moderate
Unreviewed
CVE-2026-29516
was published
Mar 16, 2026
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle...
Moderate
Unreviewed
CVE-2026-2454
was published
Mar 16, 2026
Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a...
Moderate
Unreviewed
CVE-2026-1629
was published
Mar 16, 2026
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2 fail to verify run_create permission for...
Moderate
Unreviewed
CVE-2026-26304
was published
Mar 16, 2026
An Incorrect Access Control vulnerability exists in INDEX-EDUCATION PRONOTE prior to 2025.2.8....
Moderate
Unreviewed
CVE-2025-69727
was published
Mar 16, 2026
Admidio is Missing Authorization on Forum Topic and Post Deletion
Moderate
GHSA-g375-5wmp-xr78
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Admidio has an HTMLPurifier Bypass in eCard Message Allows HTML Email Injection
Moderate
CVE-2026-32757
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Admidio Vulnerable to SSRF and Local File Read via Unrestricted URL Fetch in SSO Metadata Endpoint
Moderate
CVE-2026-32812
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Admidio is Missing CSRF Protection on Role Membership Date Changes
Moderate
CVE-2026-32755
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Admidio is Missing CSRF Validation on Role Delete, Activate, and Deactivate Actions
Moderate
GHSA-wwg8-6ffr-h4q2
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Permissive List of Allowed Inputs in ewe
Moderate
GHSA-9w88-79f8-m3vp
was published
for
ewe
(Erlang)
Mar 16, 2026
Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration
Moderate
GHSA-j94x-8wcp-x7hm
was published
for
github.com/akuity/kargo
(Go)
Mar 16, 2026
File Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination Parameter
Moderate
CVE-2026-32758
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 16, 2026
SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
Moderate
GHSA-v3mg-9v85-fcm7
was published
for
siyuan
(Go)
Mar 16, 2026
ProTip!
Advisories are also available from the
GraphQL API