GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,576 advisories
Filter by severity
Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the...
Moderate
Unreviewed
CVE-2026-11703
was published
Jun 26, 2026
A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for...
Moderate
Unreviewed
CVE-2026-13208
was published
Jun 24, 2026
Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API...
Moderate
Unreviewed
CVE-2026-34917
was published
Jun 23, 2026
Paymenter doesn't reset email verification status after email change
Moderate
CVE-2026-44584
was published
for
paymenter/paymenter
(Composer)
Jun 22, 2026
A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json...
Moderate
Unreviewed
CVE-2026-12795
was published
Jun 21, 2026
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function...
Moderate
Unreviewed
CVE-2026-12773
was published
Jun 21, 2026
capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where...
Moderate
Unreviewed
CVE-2026-56294
was published
Jun 20, 2026
Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin...
Moderate
Unreviewed
CVE-2026-56080
was published
Jun 20, 2026
Improper Authentication vulnerability in Apache APISIX.
When the cas-auth plugin is used in a...
Moderate
Unreviewed
CVE-2026-49872
was published
Jun 19, 2026
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
Moderate
CVE-2026-55689
was published
for
github.com/openfga/openfga
(Go)
Jun 19, 2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component:...
Moderate
Unreviewed
CVE-2026-35261
was published
Jun 17, 2026
Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService
Moderate
CVE-2026-50623
was published
for
org.apache.cxf:cxf-rt-rs-security-oauth2
(Maven)
Jun 12, 2026
Spring Web Services: X.509 authentication bypasses Spring Security account checks
Moderate
CVE-2026-40995
was published
for
org.springframework.ws:spring-ws-security
(Maven)
Jun 11, 2026
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
Moderate
CVE-2026-47838
was published
for
org.springframework.security:spring-security-web
(Maven)
Jun 10, 2026
A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function...
Moderate
Unreviewed
CVE-2026-11618
was published
Jun 9, 2026
An Improper Authentication vulnerability in the /api/Cdn/GetFile endpoint of linqi allows...
Moderate
Unreviewed
CVE-2026-11345
was published
Jun 5, 2026
A vulnerability was identified in ealpha072 Student-Management-System up to...
Moderate
Unreviewed
CVE-2026-10777
was published
Jun 4, 2026
A vulnerability was detected in sayan365 student-management-system up to...
Moderate
Unreviewed
CVE-2026-10619
was published
Jun 2, 2026
A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects...
Moderate
Unreviewed
CVE-2026-10617
was published
Jun 2, 2026
A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This...
Moderate
Unreviewed
CVE-2026-10288
was published
Jun 1, 2026
A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function...
Moderate
Unreviewed
CVE-2026-10283
was published
Jun 1, 2026
Claw Orchestrator is missing authentication for the component API Endpoint
Moderate
CVE-2026-10281
was published
for
@enderfga/claw-orchestrator
(npm)
Jun 1, 2026
A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is...
Moderate
Unreviewed
CVE-2026-10243
was published
Jun 1, 2026
A weakness has been identified in OUSL-GROUP-BrinaryBrains School Student Management System up to...
Moderate
Unreviewed
CVE-2026-10167
was published
May 31, 2026
A vulnerability was identified in Open5GS up to 2.7.6. This impacts an unknown function of the...
Moderate
Unreviewed
CVE-2026-10157
was published
May 31, 2026
ProTip!
Advisories are also available from the
GraphQL API