GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
598 advisories
Filter by severity
Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the...
High
Unreviewed
CVE-2026-82269
was published
Aug 28, 2026
Xiiaozet LK100Wt contains an authentication weakness within an
administrative service that may...
Critical
Unreviewed
CVE-2026-76943
was published
Aug 28, 2026
A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from...
Critical
Unreviewed
CVE-2026-65641
was published
Aug 27, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.2...
Moderate
Unreviewed
CVE-2026-3035
was published
Aug 26, 2026
In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the...
Moderate
Unreviewed
CVE-2026-58092
was published
Aug 26, 2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal...
Critical
Unreviewed
CVE-2026-16639
was published
Aug 26, 2026
The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via...
High
Unreviewed
CVE-2026-63587
was published
Aug 25, 2026
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
High
Unreviewed
CVE-2026-78259
was published
Aug 25, 2026
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
Critical
Unreviewed
CVE-2026-74001
was published
Aug 20, 2026
Subscriber Broken Authentication in Leyka <= 3.32.3 versions.
High
Unreviewed
CVE-2026-66677
was published
Aug 20, 2026
Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: from 14.1 through...
Critical
Unreviewed
CVE-2026-19490
was published
Aug 19, 2026
NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server...
High
Unreviewed
CVE-2026-24185
was published
Aug 18, 2026
An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which...
Moderate
Unreviewed
CVE-2021-43718
was published
Aug 18, 2026
Missing authentication in initial setup functionality left exposed until first reboot in GBIF...
Critical
Unreviewed
CVE-2026-71879
was published
Aug 18, 2026
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
Moderate
Unreviewed
CVE-2026-73398
was published
Aug 18, 2026
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
Moderate
Unreviewed
CVE-2026-73399
was published
Aug 18, 2026
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
Critical
Unreviewed
CVE-2026-73381
was published
Aug 18, 2026
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
High
Unreviewed
CVE-2026-73396
was published
Aug 18, 2026
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
Moderate
Unreviewed
CVE-2026-73379
was published
Aug 18, 2026
Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.
High
Unreviewed
CVE-2026-32481
was published
Aug 18, 2026
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing...
Critical
Unreviewed
CVE-2026-75627
was published
Aug 18, 2026
In JetBrains YouTrack before 2025.3.156085,
2026.1.13913,
2026.2.18112 an unauthenticated...
Critical
Unreviewed
CVE-2026-75045
was published
Aug 17, 2026
Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions.
High
Unreviewed
CVE-2026-73188
was published
Aug 13, 2026
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
Critical
Unreviewed
CVE-2026-66453
was published
Aug 13, 2026
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Critical
Unreviewed
CVE-2026-66465
was published
Aug 13, 2026
ProTip!
Advisories are also available from the
GraphQL API