GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
13 advisories
Filter by severity
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass
Critical
CVE-2026-62263
was published
for
org.openidentityplatform.openam:openam-auth-webauthn
(Maven)
Jul 24, 2026
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses
Moderate
CVE-2026-54562
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 20, 2026
Sylius: IDOR on Shop Payment Request API endpoints
Moderate
CVE-2026-53639
was published
for
sylius/sylius
(Composer)
Jul 9, 2026
Sharp Missing Authorization Check in Quick Creation Command Endpoints
Moderate
CVE-2026-53634
was published
for
code16/sharp
(Composer)
Jul 8, 2026
Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context
Moderate
CVE-2026-53521
was published
for
github.com/nezhahq/nezha
(Go)
Jun 26, 2026
Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields
Moderate
CVE-2026-48067
was published
for
filament/actions
(Composer)
Jun 11, 2026
Shopper: Authorization bypass and RBAC privilege escalation in team settings
Critical
CVE-2026-47744
was published
for
shopper/framework
(Composer)
Jun 5, 2026
Shopper: Multiple data integrity and disclosure issues in admin Livewire components
High
CVE-2026-47743
was published
for
shopper/framework
(Composer)
Jun 5, 2026
Shopper: Missing per-action authorization on PaymentMethods, Currencies and Carriers admin tables
Moderate
CVE-2026-47745
was published
for
shopper/framework
(Composer)
Jun 5, 2026
Shopper: Missing authorization on Product admin Livewire sub-form components
Moderate
CVE-2026-47742
was published
for
shopper/framework
(Composer)
Jun 5, 2026
shopper/framework: Race condition on Discount.usage_limit allows silent over-redemption
Moderate
CVE-2026-47741
was published
for
shopper/cart
(Composer)
May 18, 2026
shopper/framework: Authorization bypass in multiple Livewire admin components
High
CVE-2026-47740
was published
for
shopper/framework
(Composer)
May 18, 2026
Authenticated Sharp users can download unrelated Laravel Storage objects through the generic download endpoint
High
CVE-2026-44692
was published
for
code16/sharp
(Composer)
May 15, 2026
ProTip!
Advisories are also available from the
GraphQL API