GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,576 advisories
Filter by severity
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)
Moderate
CVE-2026-73840
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
A vulnerability was identified in tsi-coop tsi-dpdp-cms up to 0.5.0. This affects an unknown part...
Moderate
Unreviewed
CVE-2026-84840
was published
Sep 2, 2026
A vulnerability was determined in tsi-coop tsi-dpdp-cms up to 0.5.0. Affected by this issue is...
Moderate
Unreviewed
CVE-2026-84839
was published
Sep 2, 2026
A vulnerability has been identified in the underlying operating system of HPE Networking Fabric...
Moderate
Unreviewed
CVE-2026-73726
was published
Sep 1, 2026
A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the...
Moderate
Unreviewed
CVE-2026-84423
was published
Sep 2, 2026
Authentication bypasses in the API of HPE Networking Fabric Composer could allow an authenticated...
Moderate
Unreviewed
CVE-2026-73733
was published
Sep 1, 2026
The Simple Membership plugin for WordPress is vulnerable to Authentication Bypass leading to...
Moderate
Unreviewed
CVE-2026-77194
was published
Sep 1, 2026
A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the...
Moderate
Unreviewed
CVE-2026-82919
was published
Aug 31, 2026
A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown...
Moderate
Unreviewed
CVE-2026-82547
was published
Aug 30, 2026
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
Moderate
CVE-2026-55678
was published
for
github.com/basekick-labs/arc
(Go)
Aug 28, 2026
An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate...
Moderate
Unreviewed
CVE-2026-40205
was published
Aug 28, 2026
Forwarding information received from a host listed as a trusted proxy is not kept separate from...
Moderate
Unreviewed
CVE-2026-42008
was published
Aug 28, 2026
A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function...
Moderate
Unreviewed
CVE-2026-81202
was published
Aug 27, 2026
Improper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring 0: Kernel may...
Moderate
Unreviewed
CVE-2026-20752
was published
Aug 11, 2026
Improper authentication for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2...
Moderate
Unreviewed
CVE-2026-20891
was published
Aug 11, 2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require...
Moderate
Unreviewed
CVE-2026-14216
was published
Aug 26, 2026
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow an...
Moderate
Unreviewed
CVE-2025-59704
was published
Dec 2, 2025
A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the...
Moderate
Unreviewed
CVE-2026-78885
was published
Aug 25, 2026
A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of...
Moderate
Unreviewed
CVE-2026-78863
was published
Aug 25, 2026
A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController:...
Moderate
Unreviewed
CVE-2026-78434
was published
Aug 25, 2026
A vulnerability was identified in the-momentum open-wearables up to 0.6.2. This impacts the...
Moderate
Unreviewed
CVE-2026-78154
was published
Aug 24, 2026
Spring Web Services: X.509 authentication bypasses Spring Security account checks
Moderate
CVE-2026-40995
was published
for
org.springframework.ws:spring-ws-security
(Maven)
Jun 11, 2026
The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier...
Moderate
Unreviewed
CVE-2025-15671
was published
Aug 21, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2026-16972
was published
Aug 21, 2026
Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check
Moderate
CVE-2026-54176
was published
for
backpack/crud
(Composer)
Aug 20, 2026
ProTip!
Advisories are also available from the
GraphQL API