GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
4,660 advisories
Filter by severity
A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function...
Critical
Unreviewed
CVE-2026-82694
was published
Aug 31, 2026
A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of...
Critical
Unreviewed
CVE-2026-82695
was published
Aug 31, 2026
A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the...
Critical
Unreviewed
CVE-2026-82693
was published
Aug 31, 2026
Attackers can exploit command injection vulnerabilities to delete core system runtime files,...
Critical
Unreviewed
CVE-2026-49003
was published
Aug 31, 2026
A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown...
Moderate
Unreviewed
CVE-2026-82547
was published
Aug 30, 2026
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass...
High
Unreviewed
CVE-2026-75807
was published
Aug 29, 2026
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
Critical
Unreviewed
CVE-2026-82466
was published
Aug 29, 2026
@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1...
High
Unreviewed
CVE-2026-80192
was published
Aug 29, 2026
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end...
High
Unreviewed
CVE-2026-76548
was published
Aug 29, 2026
IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to...
High
Unreviewed
CVE-2026-17203
was published
Aug 29, 2026
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows...
High
Unreviewed
CVE-2026-18891
was published
Aug 29, 2026
JFrog Artifactory contains an authentication weakness that, under default configuration, may...
Critical
Unreviewed
CVE-2026-82329
was published
Aug 28, 2026
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
Moderate
CVE-2026-55678
was published
for
github.com/basekick-labs/arc
(Go)
Aug 28, 2026
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
High
CVE-2026-55761
was published
for
github.com/portainer/portainer
(Go)
Aug 28, 2026
An attacker that holds a token intended for a different purpose can authenticate, because when an...
High
Unreviewed
CVE-2026-73208
was published
Aug 28, 2026
An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate...
Moderate
Unreviewed
CVE-2026-40205
was published
Aug 28, 2026
Forwarding information received from a host listed as a trusted proxy is not kept separate from...
Moderate
Unreviewed
CVE-2026-42008
was published
Aug 28, 2026
A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an...
Critical
Unreviewed
CVE-2026-37006
was published
Aug 27, 2026
openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum...
High
Unreviewed
CVE-2026-81703
was published
Aug 27, 2026
A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function...
Moderate
Unreviewed
CVE-2026-81202
was published
Aug 27, 2026
Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication...
High
Unreviewed
CVE-2026-79938
was published
Aug 26, 2026
DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '...
Critical
Unreviewed
CVE-2026-75325
was published
Aug 26, 2026
The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin ...
High
Unreviewed
CVE-2026-19718
was published
Aug 26, 2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require...
Moderate
Unreviewed
CVE-2026-14216
was published
Aug 26, 2026
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g....
High
Unreviewed
CVE-2026-68569
was published
Aug 26, 2026
ProTip!
Advisories are also available from the
GraphQL API