GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
203 advisories
Filter by severity
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.
High
Unreviewed
CVE-2026-82225
was published
Aug 31, 2026
Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the...
High
Unreviewed
CVE-2026-82269
was published
Aug 28, 2026
The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via...
High
Unreviewed
CVE-2026-63587
was published
Aug 25, 2026
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
High
Unreviewed
CVE-2026-78259
was published
Aug 25, 2026
Subscriber Broken Authentication in Leyka <= 3.32.3 versions.
High
Unreviewed
CVE-2026-66677
was published
Aug 20, 2026
NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server...
High
Unreviewed
CVE-2026-24185
was published
Aug 18, 2026
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
High
Unreviewed
CVE-2026-73396
was published
Aug 18, 2026
Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.
High
Unreviewed
CVE-2026-32481
was published
Aug 18, 2026
Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions.
High
Unreviewed
CVE-2026-73188
was published
Aug 13, 2026
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager...
High
Unreviewed
CVE-2026-70468
was published
Aug 12, 2026
An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an...
High
Unreviewed
CVE-2026-72691
was published
Aug 10, 2026
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
High
CVE-2026-67309
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
High
Unreviewed
CVE-2026-65542
was published
Aug 6, 2026
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N...
High
Unreviewed
CVE-2026-18577
was published
Aug 3, 2026
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows...
High
Unreviewed
CVE-2026-18556
was published
Aug 1, 2026
better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when...
High
Unreviewed
CVE-2026-67337
was published
Aug 1, 2026
TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error...
High
Unreviewed
CVE-2026-12703
was published
Jul 29, 2026
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
High
Unreviewed
CVE-2026-59545
was published
Jul 23, 2026
ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are...
High
Unreviewed
CVE-2026-22049
was published
Jul 22, 2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid ...
High
Unreviewed
CVE-2026-57697
was published
Jul 13, 2026
MicroRealEstate allows adversaries to bypass authentication due to a lack of token state...
High
Unreviewed
CVE-2026-57867
was published
Jul 7, 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
High
CVE-2026-50194
was published
for
Steeltoe.Management.Endpoint
(NuGet)
Jul 2, 2026
AS228T with Authentication Bypass Vulnerability
High
Unreviewed
CVE-2026-12579
was published
Jul 1, 2026
Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.
High
Unreviewed
CVE-2026-56029
was published
Jun 26, 2026
Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS...
High
Unreviewed
CVE-2026-56243
was published
Jun 23, 2026
ProTip!
Advisories are also available from the
GraphQL API