GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,521
Maven
5,000+
npm
5,000+
NuGet
911
pip
4,760
Pub
13
RubyGems
1,036
Rust
1,229
Swift
53
Unreviewed advisories
All unreviewed
5,000+
7,083 advisories
Filter by severity
Missing Authorization vulnerability in Plisio Accept Cryptocurrencies with Plisio allows...
High
Unreviewed
CVE-2026-6372
was published
Apr 15, 2026
The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations...
Critical
Unreviewed
CVE-2026-5387
was published
Apr 15, 2026
Missing Authorization vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows...
Moderate
Unreviewed
CVE-2026-40742
was published
Apr 15, 2026
Missing Authorization vulnerability in BlockArt Magazine Blocks magazine-blocks allows Exploiting...
Moderate
Unreviewed
CVE-2026-40728
was published
Apr 15, 2026
The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to...
Moderate
Unreviewed
CVE-2025-15565
was published
Apr 15, 2026
Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Action
Moderate
GHSA-jq2f-59pj-p3m3
was published
for
craftcms/cms
(Composer)
Apr 14, 2026
Decidim's comments API allows access to all commentable resources
High
CVE-2026-40870
was published
for
decidim-api
(RubyGems)
Apr 14, 2026
The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for...
Moderate
Unreviewed
CVE-2026-4109
was published
Apr 14, 2026
Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an...
Moderate
Unreviewed
CVE-2026-34261
was published
Apr 14, 2026
Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise),...
High
Unreviewed
CVE-2026-34256
was published
Apr 14, 2026
The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing...
Critical
Unreviewed
CVE-2026-4365
was published
Apr 14, 2026
Craft Commerce has an unauthenticated information disclosure that can leak some customer order data on anonymous payments
Low
CVE-2026-32270
was published
for
craftcms/commerce
(Composer)
Apr 14, 2026
Due to missing authorization checks in the SAP S/4HANA backend OData Service (Manage Reference...
Moderate
Unreviewed
CVE-2026-27678
was published
Apr 14, 2026
The Material Master application does not enforce authorization checks for authenticated users...
Moderate
Unreviewed
CVE-2026-27672
was published
Apr 14, 2026
Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference...
Moderate
Unreviewed
CVE-2026-27679
was published
Apr 14, 2026
Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Reference Equipment)...
Moderate
Unreviewed
CVE-2026-27677
was published
Apr 14, 2026
Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an...
Moderate
Unreviewed
CVE-2026-27673
was published
Apr 14, 2026
Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Technical Object...
Moderate
Unreviewed
CVE-2026-27676
was published
Apr 14, 2026
Note Mark has Broken Access Control on Asset Download
Moderate
CVE-2026-40265
was published
for
github.com/enchant97/note-mark/backend
(Go)
Apr 13, 2026
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-3358
was published
Apr 11, 2026
paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass
Critical
GHSA-68qg-g8mg-6pr7
was published
for
@paperclipai/server
(npm)
Apr 10, 2026
goshs has a file-based ACL authorization bypass in goshs state-changing routes
Critical
CVE-2026-40189
was published
for
github.com/patrickhener/goshs
(Go)
Apr 10, 2026
Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure
Moderate
GHSA-w8jj-cwmc-wgq2
was published
for
github.com/lin-snow/ech0
(Go)
Apr 10, 2026
Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass
Moderate
GHSA-fwg7-53p4-g33c
was published
for
github.com/lin-snow/ech0
(Go)
Apr 10, 2026
Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs
Moderate
GHSA-cp79-9mwr-wr49
was published
for
github.com/lin-snow/ech0
(Go)
Apr 10, 2026
ProTip!
Advisories are also available from the
GraphQL API