Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,576 advisories

Loading
A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for... Moderate Unreviewed
CVE-2026-13208 was published Jun 24, 2026
Paymenter doesn't reset email verification status after email change Moderate
CVE-2026-44584 was published for paymenter/paymenter (Composer) Jun 22, 2026
ljskatt Credited to ljskatt and CorwinDev CorwinDev CorwinDev
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function... Moderate Unreviewed
CVE-2026-12773 was published Jun 21, 2026
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset Moderate
CVE-2026-55689 was published for github.com/openfga/openfga (Go) Jun 19, 2026
0xVijay Credited to 0xVijay
Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService Moderate
CVE-2026-50623 was published for org.apache.cxf:cxf-rt-rs-security-oauth2 (Maven) Jun 12, 2026
Spring Web Services: X.509 authentication bypasses Spring Security account checks Moderate
CVE-2026-40995 was published for org.springframework.ws:spring-ws-security (Maven) Jun 11, 2026
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates Moderate
CVE-2026-47838 was published for org.springframework.security:spring-security-web (Maven) Jun 10, 2026
marcelstoer Credited to marcelstoer and julianladisch julianladisch julianladisch
A vulnerability was identified in ealpha072 Student-Management-System up to... Moderate Unreviewed
CVE-2026-10777 was published Jun 4, 2026
A vulnerability was detected in sayan365 student-management-system up to... Moderate Unreviewed
CVE-2026-10619 was published Jun 2, 2026
Claw Orchestrator is missing authentication for the component API Endpoint Moderate
CVE-2026-10281 was published for @enderfga/claw-orchestrator (npm) Jun 1, 2026
ProTip! Advisories are also available from the GraphQL API