GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
87 advisories
Filter by severity
The affected Ebyte
product's vendor configuration utility permits access to administrative ...
Critical
Unreviewed
CVE-2026-73819
was published
Aug 31, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an...
High
Unreviewed
CVE-2026-65098
was published
Aug 25, 2026
The login endpoint on the Mira cloud API accepts any format-valid string in the password field...
Critical
Unreviewed
CVE-2026-68067
was published
Aug 12, 2026
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to...
Moderate
Unreviewed
CVE-2026-59135
was published
Aug 11, 2026
Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
High
Unreviewed
CVE-2026-59554
was published
Jul 23, 2026
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive...
High
Unreviewed
CVE-2026-50756
was published
Jul 21, 2026
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a...
Critical
Unreviewed
CVE-2026-55040
was published
Jul 14, 2026
A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to...
High
Unreviewed
CVE-2026-10714
was published
Jul 14, 2026
Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and...
Moderate
Unreviewed
CVE-2026-57352
was published
Jul 2, 2026
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for...
High
Unreviewed
CVE-2026-0274
was published
Jun 11, 2026
AVideo's Meet plugin: `uploadRecordedVideo.json.php` derives `users_id` from the uploaded filename and calls passwordless `User->login()`, allowing any caller with the Meet shared secret to obtain a session as arbitrary users including admin
High
GHSA-qxvm-r42f-5p8j
was published
for
WWBN/AVideo
(Composer)
May 15, 2026
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-40417
was published
May 12, 2026
Unity Catalog has a JWT Issuer Validation Bypass tht Allows Complete User Impersonation
Critical
CVE-2026-27478
was published
for
io.unitycatalog:unitycatalog-server
(Maven)
May 11, 2026
Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication...
High
Unreviewed
CVE-2025-70994
was published
Apr 23, 2026
Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication...
Critical
Unreviewed
CVE-2026-6886
was published
Apr 23, 2026
Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and...
High
Unreviewed
CVE-2026-4828
was published
Apr 1, 2026
Improper
authentication in the two-factor authentication (2FA) feature in
Devolutions Server...
High
Unreviewed
CVE-2026-4924
was published
Apr 1, 2026
Weak Authentication vulnerability in PickPlugins User Verification user-verification allows...
Moderate
Unreviewed
CVE-2026-32497
was published
Mar 25, 2026
A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local...
Moderate
Unreviewed
CVE-2025-62844
was published
Mar 20, 2026
Sensitive information disclosure and manipulation due to improper authentication. The following...
High
Unreviewed
CVE-2026-28710
was published
Mar 6, 2026
Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.
Moderate
Unreviewed
CVE-2025-15595
was published
Mar 3, 2026
Sensitive data disclosure and manipulation due to improper authentication. The following products...
Critical
Unreviewed
CVE-2025-30411
was published
Feb 20, 2026
Sensitive data disclosure and manipulation due to improper authentication. The following products...
Critical
Unreviewed
CVE-2025-30412
was published
Feb 20, 2026
A weak authentication vulnerability has been reported to affect File Station 5. The remote...
Low
Unreviewed
CVE-2025-57713
was published
Feb 11, 2026
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability...
Critical
Unreviewed
CVE-2025-40554
was published
Jan 28, 2026
ProTip!
Advisories are also available from the
GraphQL API