GitHub Security Advisories
Open-source package ecosystem coverage across npm / PyPI / Maven / Go / RubyGems and more.
47,163 advisories tracked · showing 100
- Sep 19, 2026GHSA-53vp-fjc5-cqj6MediumCVSS 5.3CVE-2026-89093
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for...
- Sep 19, 2026GHSA-mff9-5jrw-3j2mMediumCVSS 6.1CVE-2026-89081
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to...
- Sep 19, 2026GHSA-4f44-p79q-6vj4MediumCVSS 6.5CVE-2026-89334
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for...
- Sep 19, 2026GHSA-95p6-v6qj-q4v6MediumCVSS 4.3CVE-2026-88944
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to...
- Sep 19, 2026GHSA-fjhh-mxpw-32j7MediumCVSS 6.5CVE-2026-89333
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to...
- Sep 19, 2026GHSA-54jx-f43m-h839MediumCVSS 6.1CVE-2026-92967
The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword...
- Sep 19, 2026GHSA-3fg9-62hh-37mhHighCVSS 8.8CVE-2026-92807
The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function...
- Sep 19, 2026GHSA-2vrv-wr6r-v79vCriticalCVSS 9.1CVE-2026-92229
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress...
- Sep 19, 2026GHSA-x57m-9xmj-gh9pCriticalCVSS 9.1CVE-2026-89274
The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all...
- Sep 19, 2026GHSA-hcxp-7h6p-263rMediumCVSS 6.5CVE-2026-15760
The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in...
- Sep 19, 2026GHSA-79fj-jcjp-5w4vMediumCVSS 6.4CVE-2026-77820
The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty'...
- Sep 19, 2026GHSA-q642-cfr5-5536MediumCVSS 4.3CVE-2026-15660
The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to,...
- Sep 19, 2026GHSA-7gwr-8m73-rgp7HighCVSS 7.2CVE-2026-13354
The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site...
- Sep 19, 2026GHSA-mx4x-6r5x-jrh9HighCVSS 7.5CVE-2026-87909
The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all...
- Sep 19, 2026GHSA-x9x4-5g6j-pvj3CriticalCVSS 9.8CVE-2026-84434
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up...
- Sep 19, 2026GHSA-5v5w-p5x3-68gqMediumCVSS 4.4CVE-2026-12042
The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
- Sep 19, 2026GHSA-j5v6-qhh5-48r7MediumCVSS 4.3CVE-2026-93921
SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon...
- Sep 19, 2026GHSA-jfm6-64hf-4hh9HighCVSS 8.8CVE-2026-93922
SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without...
- Sep 19, 2026GHSA-qvp6-cjg5-8753HighCVSS 8.8CVE-2026-93923
SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark...
- Sep 19, 2026GHSA-92ph-4c2m-29x6MediumCVE-2026-77875
The application protects access through its calculator-style vault passcode, but the stored data...
- Sep 19, 2026GHSA-p889-mw66-wfh2CriticalCVSS 10.0CVE-2026-93740
A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function...
- Sep 19, 2026GHSA-hm52-6738-r26pCriticalCVSS 9.3CVE-2026-75885
A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `...
- Sep 19, 2026GHSA-8f83-mv8g-3hmrHighCVSS 9.9CVE-2026-93739
A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function...
- Sep 18, 2026GHSA-c599-gp9v-cp79MediumCVSS 6.5CVE-2026-93562
A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding...
- Sep 18, 2026GHSA-h9w4-646p-4c73HighCVSS 8.1CVE-2026-88097
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate...
- Sep 18, 2026GHSA-cvqm-vq22-35jfHighCVSS 9.9CVE-2026-93738
A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function...
- Sep 18, 2026GHSA-pfj3-384h-g8q8LowCVE-2026-93894
In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper()...
- Sep 18, 2026GHSA-c9wq-39xx-437pMediumCVSS 6.5CVE-2026-93574
A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this...
- Sep 18, 2026GHSA-2wj2-6xq8-f5rxMediumCVSS 6.0CVE-2026-91203
A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing...
- Sep 18, 2026GHSA-wr7x-wjmq-6p9vHighCVSS 8.1CVE-2026-84108
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to...
- Sep 18, 2026GHSA-hqvg-3pmx-hpp4HighCVSS 7.7CVE-2026-84105
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive...
- Sep 18, 2026GHSA-75j4-w6hg-5w3rHighCVSS 8.9CVE-2026-84106
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute...
- Sep 18, 2026GHSA-97fp-7cr2-23qcMediumCVSS 3.7CVE-2026-93840
vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output...
- Sep 18, 2026GHSA-4mgj-9vmr-j9cjHighCVSS 8.1CVE-2026-84085
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands...
- Sep 18, 2026GHSA-5jj9-v4xp-h5h5MediumCVSS 6.0CVE-2026-91205
A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition...
- Sep 18, 2026GHSA-fx98-4ggj-ff23MediumCVSS 4.3CVE-2026-93873
Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler...
- Sep 18, 2026GHSA-8j2j-pv92-9h77HighCVSS 8.1CVE-2026-84241
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions...
- Sep 18, 2026GHSA-88xg-pjv8-gq33HighCVSS 7.6CVE-2026-84239
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive...
- Sep 18, 2026GHSA-644q-7756-5g89CriticalCVSS 9.8CVE-2026-93839
LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register...
- Sep 18, 2026GHSA-q9hm-g73w-q6wpMediumCVSS 3.7CVE-2026-93841
vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel...
- Sep 18, 2026GHSA-rw92-cwm5-wp25CriticalCVSS 8.1CVE-2026-93868
Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users...
- Sep 18, 2026GHSA-2g9g-mfvg-w359MediumCVSS 6.1CVE-2026-91202
A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by...
- Sep 18, 2026GHSA-v278-3mjv-f38gHighCVSS 8.8CVE-2026-93031
The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for...
- Sep 18, 2026GHSA-3v3g-3pf9-fgcfHighCVSS 7.5CVE-2026-93872
Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes...
- Sep 18, 2026GHSA-5p43-vwpq-wm4qMediumCVSS 6.1CVE-2026-93869
Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function...
- Sep 18, 2026GHSA-2wcg-j54r-m6wmHighCVSS 5.9CVE-2026-93838
SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in...
- Sep 18, 2026GHSA-7h6q-853g-5r6cMediumCVSS 4.3CVE-2026-93870
Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler,...
- Sep 18, 2026GHSA-gp9j-h9gm-p3q2MediumCVSS 5.4CVE-2026-93871
Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:...
- Sep 18, 2026GHSA-fgpf-phpq-hchqHighCVSS 8.1CVE-2026-82892
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due...
- Sep 18, 2026GHSA-7jhh-r4p3-5p6rHighCVSS 8.8CVE-2026-81656
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query...
- Sep 18, 2026GHSA-g38r-cx9q-54vqCriticalCVSS 9.8CVE-2026-80441
IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection...
- Sep 18, 2026GHSA-m3rh-r6pf-7qmhCriticalCVSS 9.9CVE-2026-80442
IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection...
- Sep 18, 2026GHSA-wgrq-mg2c-2hgvHighCVSS 8.8CVE-2026-81933
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic...
- Sep 18, 2026GHSA-r8w2-vmwg-p5x9HighCVSS 7.2CVE-2026-81937
IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the...
- Sep 18, 2026GHSA-ccxw-2xjr-78f5MediumCVSS 6.3CVE-2026-81623
IBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands...
- Sep 18, 2026GHSA-mf93-58gc-8fqqCriticalCVSS 9.8CVE-2026-82340
IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and...
- Sep 18, 2026GHSA-96vj-x6rv-cjrfCriticalCVSS 9.8CVE-2026-82967
IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an...
- Sep 18, 2026GHSA-h3pv-6pq6-64wqCriticalCVSS 9.8CVE-2026-81657
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute...
- Sep 18, 2026GHSA-92hg-9mjw-cm5qCriticalCVSS 9.6CVE-2026-82832
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute...
- Sep 18, 2026GHSA-v894-328c-wpqfHighCVSS 7.8CVE-2026-82893
IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to...
- Sep 18, 2026GHSA-p4f3-jghx-wq4rHighCVSS 7.2CVE-2026-84071
IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal...
- Sep 18, 2026GHSA-97mm-h99g-pggxHighCVSS 7.2CVE-2026-81669
IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the...
- Sep 18, 2026GHSA-rp9w-fccr-c4mmHighCVSS 8.8CVE-2026-82885
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated...
- Sep 18, 2026GHSA-42xx-84f6-wh3rMediumCVSS 5.9CVE-2026-82890
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute...
- Sep 18, 2026GHSA-w2vr-g8ch-fvgcHighCVSS 8.1CVE-2026-84081
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions...
- Sep 18, 2026GHSA-9h47-v7vr-8c8mHighCVSS 8.6CVE-2026-81626
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load...
- Sep 18, 2026GHSA-2mx2-rwj3-9p8jHighCVSS 7.6CVE-2026-82896
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse...
- Sep 18, 2026GHSA-5rg7-x363-pvjpHighCVSS 8.8CVE-2026-82887
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute...
- Sep 18, 2026GHSA-j3hx-vgc4-fhh3CriticalCVSS 9.9CVE-2026-84078
IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the...
- Sep 18, 2026GHSA-qq6f-r3p5-823pHighCVSS 8.8CVE-2026-84034
IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the...
- Sep 18, 2026GHSA-7qhf-gchx-2gpxCriticalCVSS 9.1CVE-2026-84073
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute...
- Sep 18, 2026GHSA-fmv8-fq3w-c796HighCVSS 7.4CVE-2026-84036
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security...
- Sep 18, 2026GHSA-6mxc-qwwc-vccwCriticalCVSS 9.0CVE-2026-84031
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute...
- Sep 18, 2026GHSA-6j6w-pmcv-gghmHighCVSS 8.9CVE-2026-84070
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute...
- Sep 18, 2026GHSA-r88h-xfv7-89vxCriticalCVSS 9.9CVE-2026-84064
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute...
- Sep 18, 2026GHSA-6wff-gp7v-cffjHighCVSS 7.8CVE-2026-84083
IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root...
- Sep 18, 2026GHSA-p9p9-q9h9-qrvqHighCVSS 8.9CVE-2026-84074
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute...
- Sep 18, 2026GHSA-65v8-c3hg-r84pHighCVSS 7.6CVE-2026-84076
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security...
- Sep 18, 2026GHSA-ffcm-fpqj-4f8cHighCVSS 8.8CVE-2026-84084
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions...
- Sep 18, 2026GHSA-mw26-mw57-3h52HighCVSS 7.8CVE-2026-84089
IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to...
- Sep 18, 2026GHSA-8x2r-f5pm-qh9hCriticalCVSS 9.8CVE-2026-84082
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands...
- Sep 18, 2026GHSA-qhrr-29qr-vpr5CriticalCVSS 9.9CVE-2026-84075
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions...
- Sep 18, 2026GHSA-q2f2-p9wg-qv6fHighCVSS 8.1CVE-2026-84077
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions...
- Sep 18, 2026GHSA-v325-fqcr-w6gcHighCVSS 7.2CVE-2026-84086
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute...
- Sep 18, 2026GHSA-mr8w-j3pv-4wm8MediumCVSS 5.4CVE-2026-17262
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to...
- Sep 18, 2026GHSA-7mfh-r2p9-v6hcHighCVSS 8.6CVE-2026-17619
IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted...
- Sep 18, 2026GHSA-6r76-w3vq-7277HighCVSS 8.1CVE-2026-11726
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain...
- Sep 18, 2026GHSA-f4rg-wq5h-c9ccMediumCVSS 4.8CVE-2026-11722
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP...
- Sep 18, 2026GHSA-qxf8-2p95-9hvvMediumCVSS 6.5CVE-2026-11711
IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in...
- Sep 18, 2026GHSA-7v82-2f2m-8pjmHighCVSS 8.1CVE-2026-11727
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to...
- Sep 18, 2026GHSA-428g-q4g3-3qv6HighCVSS 7.5CVE-2026-11716
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a...
- Sep 18, 2026GHSA-w35j-3p8f-wphjHighCVSS 8.8CVE-2026-11725
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute...
- Sep 18, 2026GHSA-m47x-fj2g-vfr5MediumCVSS 6.4CVE-2026-18869
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security...
- Sep 18, 2026GHSA-fpm9-38vr-4gp8unknownCVE-2026-75895
In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack()...
- Sep 18, 2026GHSA-652p-cfff-8crmCriticalCVSS 9.1CVE-2026-75878
IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a...
- Sep 18, 2026GHSA-r353-h774-697mMediumCVSS 5.3CVE-2026-11539
IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass...
- Sep 18, 2026GHSA-g4v5-w6q6-j5cqunknownCVE-2026-75894
In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt()...
- Sep 18, 2026GHSA-5p56-5h9g-2gjvunknownCVE-2026-75893
In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the...
- Sep 18, 2026GHSA-mp35-rp3g-prrgunknownCVE-2026-75892
In osmo-ggsn 1.14.0 an out of bounds write issue was found in the gtp_decode_pdp_ctx() function...
- Sep 18, 2026GHSA-rf22-mxh9-4qvfHighCVE-2026-93852
In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases...