GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
3,841 advisories
Filter by severity
etcd: Watch API authorization bypass via open-ended range requests
High
GHSA-xg4h-6gfc-h4m8
was published
for
go.etcd.io/etcd/v3
(Go)
Jul 24, 2026
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Moderate
GHSA-v6w6-358x-2433
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
High
GHSA-47w6-gwp4-w6vc
was published
for
vantage6
(pip)
Jul 24, 2026
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored
Moderate
CVE-2026-62323
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
High
GHSA-xcx6-4f2g-hhgx
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Privilege escalation via public role assignment API missing app-level authorization
High
GHSA-j9fc-w3mr-x6mv
was published
for
@budibase/server
(npm)
Jul 24, 2026
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Moderate
CVE-2026-59212
was published
for
open-webui
(pip)
Jul 24, 2026
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials
High
CVE-2026-55502
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings
Moderate
CVE-2026-55499
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
A flaw was found in pki-core. The certificate authority (CA) renewal request path does not...
Low
Unreviewed
CVE-2026-17039
was published
Jul 24, 2026
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Moderate
CVE-2026-59217
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
Moderate
CVE-2026-59227
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Low
CVE-2026-59226
was published
for
open-webui
(pip)
Jul 24, 2026
@better-auth/stripe: cross-organization billing tampering in organization subscription actions
High
GHSA-h3rm-78g3-j7cp
was published
for
@better-auth/stripe
(npm)
Jul 24, 2026
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due...
High
Unreviewed
CVE-2026-8789
was published
Jul 24, 2026
ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219
Moderate
GHSA-56m6-8q75-f2rw
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount...
High
Unreviewed
CVE-2026-59678
was published
Jul 23, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Moderate
GHSA-h5v5-8746-g7mm
was published
for
jupyterlab
(pip)
Jul 22, 2026
n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
Moderate
CVE-2026-65596
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
Moderate
CVE-2026-65594
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
High
GHSA-cj9h-qx8g-pq2g
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
High
GHSA-6qc9-mqvw-jg7x
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
High
GHSA-64xh-79j6-r5v8
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
High
GHSA-8342-988q-86cr
was published
for
n8n
(npm)
Jul 22, 2026
An authenticated user may be able to view session metadata belonging to other users on the system...
Moderate
Unreviewed
CVE-2026-13061
was published
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API