GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
4,682 advisories
Filter by severity
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)
Moderate
CVE-2026-73840
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge
High
CVE-2026-62669
was published
for
getgrav/grav
(Composer)
Sep 2, 2026
A vulnerability was identified in tsi-coop tsi-dpdp-cms up to 0.5.0. This affects an unknown part...
Moderate
Unreviewed
CVE-2026-84840
was published
Sep 2, 2026
A vulnerability was determined in tsi-coop tsi-dpdp-cms up to 0.5.0. Affected by this issue is...
Moderate
Unreviewed
CVE-2026-84839
was published
Sep 2, 2026
An authentication vulnerability exists in the AOS-CX management interface and API that may allow...
High
Unreviewed
CVE-2026-73771
was published
Sep 1, 2026
An authentication bypass vulnerability exists in the underlying operating system of HPE...
Critical
Unreviewed
CVE-2026-19766
was published
Sep 1, 2026
A vulnerability exists in the affected products that allows a threat actor to gain access to user...
High
Unreviewed
CVE-2024-7956
was published
Sep 2, 2026
A vulnerability has been identified in the underlying operating system of HPE Networking Fabric...
Moderate
Unreviewed
CVE-2026-73726
was published
Sep 1, 2026
JFrog Artifactory contains an authentication weakness that, under default configuration, may...
Critical
Unreviewed
CVE-2026-82329
was published
Aug 28, 2026
Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could...
High
Unreviewed
CVE-2026-73777
was published
Sep 1, 2026
Vulnerabilities have been identified in the operating system of AOS-CX switches that could...
High
Unreviewed
CVE-2026-73764
was published
Sep 1, 2026
Craft CMS has a potential information disclosure vulnerability in preview tokens
Low
CVE-2026-29113
was published
for
craftcms/cms
(Composer)
Mar 10, 2026
The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion...
High
Unreviewed
CVE-2026-82183
was published
Sep 2, 2026
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the...
High
Unreviewed
CVE-2026-12526
was published
Sep 2, 2026
A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the...
Moderate
Unreviewed
CVE-2026-84423
was published
Sep 2, 2026
Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could...
Critical
Unreviewed
CVE-2026-76657
was published
Sep 1, 2026
A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that...
Critical
Unreviewed
CVE-2026-76658
was published
Sep 1, 2026
Authentication bypasses in the API of HPE Networking Fabric Composer could allow an authenticated...
Moderate
Unreviewed
CVE-2026-73733
was published
Sep 1, 2026
Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled
High
CVE-2026-77567
was published
for
filament/filament
(Composer)
Sep 1, 2026
A vulnerability has been found in Cleo Harmony up to 5.8.1.10. Impacted is the function...
Low
Unreviewed
CVE-2026-84114
was published
Sep 1, 2026
The Simple Membership plugin for WordPress is vulnerable to Authentication Bypass leading to...
Moderate
Unreviewed
CVE-2026-77194
was published
Sep 1, 2026
The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System...
High
Unreviewed
CVE-2026-19806
was published
Sep 1, 2026
A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the...
Moderate
Unreviewed
CVE-2026-82919
was published
Aug 31, 2026
A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the...
Low
Unreviewed
CVE-2026-82906
was published
Aug 31, 2026
Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0:...
High
Unreviewed
CVE-2026-20885
was published
Aug 11, 2026
ProTip!
Advisories are also available from the
GraphQL API