GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,967
Maven
5,000+
npm
5,000+
NuGet
973
pip
5,000+
Pub
13
RubyGems
1,064
Rust
1,387
Swift
56
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,624 advisories
Filter by severity
NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A...
Critical
Unreviewed
CVE-2025-71318
was published
Jun 5, 2026
Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an...
Moderate
Unreviewed
CVE-2026-11238
was published
Jun 5, 2026
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run...
High
Unreviewed
CVE-2024-27890
was published
Jun 5, 2026
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run...
High
Unreviewed
CVE-2024-27892
was published
Jun 5, 2026
Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution...
Critical
Unreviewed
CVE-2026-25550
was published
Jun 4, 2026
WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that...
Critical
Unreviewed
CVE-2019-25738
was published
Jun 4, 2026
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing...
High
Unreviewed
CVE-2026-50225
was published
Jun 4, 2026
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions...
High
Unreviewed
CVE-2026-36603
was published
Jun 3, 2026
Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an...
Critical
Unreviewed
CVE-2026-0611
was published
Jun 2, 2026
Cryptographic Issue while processing a specific partition which allows unauthorized write access...
High
Unreviewed
CVE-2026-24088
was published
Jun 2, 2026
Cryptographic issue while processing partition table entries allows unauthorized modification of...
High
Unreviewed
CVE-2026-24090
was published
Jun 2, 2026
Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated...
Critical
Unreviewed
CVE-2018-25412
was published
May 30, 2026
There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard...
Critical
Unreviewed
CVE-2026-9051
was published
May 29, 2026
The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT...
High
Unreviewed
CVE-2026-5768
was published
May 29, 2026
Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without...
High
Unreviewed
CVE-2026-49195
was published
May 29, 2026
The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator...
Critical
Unreviewed
CVE-2026-8732
was published
May 29, 2026
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal...
High
Unreviewed
CVE-2026-46826
was published
May 28, 2026
Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64...
High
Unreviewed
CVE-2026-8697
was published
May 28, 2026
Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP...
Critical
Unreviewed
CVE-2026-8364
was published
May 27, 2026
FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no...
High
Unreviewed
CVE-2026-48692
was published
May 26, 2026
A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP...
Critical
Unreviewed
CVE-2026-9152
was published
May 21, 2026
Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass...
Critical
Unreviewed
CVE-2026-9141
was published
May 20, 2026
A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload...
Critical
Unreviewed
CVE-2026-20223
was published
May 20, 2026
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could...
High
Unreviewed
CVE-2026-8602
was published
May 19, 2026
API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication...
Critical
Unreviewed
CVE-2026-31071
was published
May 19, 2026
ProTip!
Advisories are also available from the
GraphQL API