GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,521
Maven
5,000+
npm
5,000+
NuGet
912
pip
4,768
Pub
13
RubyGems
1,036
Rust
1,229
Swift
53
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
3,698 advisories
Filter by severity
The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of...
Critical
Unreviewed
CVE-2026-4880
was published
Apr 16, 2026
Improper privilege management in Microsoft Windows allows an authorized attacker to deny service...
Moderate
Unreviewed
CVE-2026-32181
was published
Apr 14, 2026
The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all...
High
Unreviewed
CVE-2026-5144
was published
Apr 11, 2026
The pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate...
High
Unreviewed
CVE-2026-29923
was published
Apr 9, 2026
An issue that allowed all-organization administrators to promote accounts to superuser status has...
High
Unreviewed
CVE-2026-5373
was published
Apr 7, 2026
HiSecOS web server contains a privilege escalation vulnerability that allows authenticated users...
High
Unreviewed
CVE-2023-7343
was published
Apr 2, 2026
HiSecOS web server contains a privilege escalation vulnerability that allows authenticated users...
High
Unreviewed
CVE-2023-7342
was published
Apr 2, 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
High
Unreviewed
CVE-2024-44250
was published
Apr 2, 2026
The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in...
High
Unreviewed
CVE-2026-2931
was published
Mar 26, 2026
An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to...
Critical
Unreviewed
CVE-2025-70888
was published
Mar 25, 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4...
Moderate
Unreviewed
CVE-2026-28889
was published
Mar 25, 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2026-20607
was published
Mar 25, 2026
The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2026-4314
was published
Mar 22, 2026
The Import and export users and customers plugin for WordPress is vulnerable to privilege...
High
Unreviewed
CVE-2026-3629
was published
Mar 22, 2026
The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-2375
was published
Mar 21, 2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo PC...
Moderate
Unreviewed
CVE-2026-2640
was published
Mar 11, 2026
Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Privilege...
Moderate
Unreviewed
CVE-2026-24510
was published
Mar 11, 2026
Improper Privilege Management in certain Zoom Clients for Windows may allow an authenticated user...
High
Unreviewed
CVE-2026-30902
was published
Mar 11, 2026
The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Improper...
High
Unreviewed
CVE-2026-1993
was published
Mar 11, 2026
The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST...
Critical
Unreviewed
CVE-2026-2631
was published
Mar 11, 2026
By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow...
High
Unreviewed
CVE-2025-15547
was published
Mar 9, 2026
If two sibling jails are restricted to separate filesystem trees, which is to say that neither of...
High
Unreviewed
CVE-2025-15576
was published
Mar 9, 2026
The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2025-8899
was published
Mar 7, 2026
An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc...
Critical
Unreviewed
CVE-2025-29165
was published
Mar 5, 2026
An authorization bypass vulnerability in Tata Consultancy Services Cognix Recon Client v3.0...
High
Unreviewed
CVE-2026-26416
was published
Mar 5, 2026
ProTip!
Advisories are also available from the
GraphQL API