GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,576 advisories
Filter by severity
russh server userauth state is not reset when authentication principal changes
Moderate
CVE-2026-46705
was published
for
russh
(Rust)
May 29, 2026
FUXA provides guest and invalid-token access to protected read APIs in secure mode
Moderate
CVE-2026-47718
was published
for
fuxa-server
(npm)
May 28, 2026
Casdoor allows users to bypass configured MFA requirements
Moderate
CVE-2026-9091
was published
for
github.com/casdoor/casdoor
(Go)
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Moderate
CVE-2026-45754
was published
for
symfony/lox24-notifier
(Composer)
May 28, 2026
A vulnerability has been found in JeecgBoot 3.9.1. This issue affects some unknown processing of...
Moderate
Unreviewed
CVE-2026-9373
was published
May 26, 2026
Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance
Moderate
CVE-2026-46715
was published
for
Flask-Security-Too
(pip)
May 22, 2026
ImageMagick: Heap Buffer Over-Read in distributed pixel cache server
Moderate
CVE-2026-47166
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 22, 2026
ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative...
Moderate
Unreviewed
CVE-2026-2812
was published
May 20, 2026
MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing...
Moderate
Unreviewed
CVE-2026-9084
was published
May 20, 2026
Improper Authentication vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before...
Moderate
Unreviewed
CVE-2026-31387
was published
May 19, 2026
A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function...
Moderate
Unreviewed
CVE-2026-8737
was published
May 17, 2026
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE
Moderate
GHSA-wxw3-q3m9-c3jr
was published
for
better-auth
(npm)
May 15, 2026
slack-go `SecretsVerifier` accepts empty signing secret without precondition
Moderate
GHSA-gxhx-2686-5h9g
was published
for
github.com/slack-go/slack
(Go)
May 14, 2026
OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover
Moderate
CVE-2026-44720
was published
for
openlearnx
(npm)
May 13, 2026
A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function...
Moderate
Unreviewed
CVE-2026-8321
was published
May 11, 2026
A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function...
Moderate
Unreviewed
CVE-2026-8305
was published
May 11, 2026
A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This...
Moderate
Unreviewed
CVE-2026-8244
was published
May 10, 2026
A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This issue...
Moderate
Unreviewed
CVE-2026-8216
was published
May 10, 2026
A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. This affects...
Moderate
Unreviewed
CVE-2026-8214
was published
May 10, 2026
A security vulnerability has been detected in UGREEN CM933 1.1.59.4319. The impacted element is...
Moderate
Unreviewed
CVE-2026-8185
was published
May 9, 2026
A vulnerability was detected in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected...
Moderate
Unreviewed
CVE-2026-8031
was published
May 6, 2026
PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade
Moderate
CVE-2026-44166
was published
for
github.com/pocketbase/pocketbase
(Go)
May 5, 2026
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
Moderate
CVE-2026-42041
was published
for
axios
(npm)
May 5, 2026
OpenClaw's Gateway Control UI bootstrap config required Gateway auth
Moderate
GHSA-93rg-2xm5-2p9v
was published
for
openclaw
(npm)
May 4, 2026
A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue...
Moderate
Unreviewed
CVE-2026-7714
was published
May 4, 2026
ProTip!
Advisories are also available from the
GraphQL API