GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
251 advisories
Filter by severity
ELECOM wireless LAN access point devices do not require authentication to access some specific...
Critical
Unreviewed
CVE-2026-40621
was published
May 13, 2026
DevGuard has an unauthenticated identity assertion via `X-Admin-Token` header
Critical
CVE-2026-42300
was published
for
github.com/l3montree-dev/devguard
(Go)
May 5, 2026
The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass...
Critical
Unreviewed
CVE-2026-7458
was published
May 2, 2026
The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to...
Critical
Unreviewed
CVE-2026-7567
was published
May 1, 2026
A vulnerability in
SenseLive
X3050’s web management interface allows unauthorized access to...
Critical
Unreviewed
CVE-2026-40630
was published
Apr 24, 2026
The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all...
Critical
Unreviewed
CVE-2026-3461
was published
Apr 22, 2026
Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150.
Critical
Unreviewed
CVE-2026-6768
was published
Apr 21, 2026
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and...
Critical
Unreviewed
CVE-2026-6771
was published
Apr 21, 2026
Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150.
Critical
Unreviewed
CVE-2026-6760
was published
Apr 21, 2026
megagao production_ssm v1.0 contains an authorization bypass vulnerability in the user addition...
Critical
Unreviewed
CVE-2026-31271
was published
Apr 7, 2026
In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during...
Critical
Unreviewed
CVE-2026-30079
was published
Apr 7, 2026
An issue in the login mechanism of Kaleris YMS v7.2.2.1 allows attackers to bypass login...
Critical
Unreviewed
CVE-2026-31151
was published
Apr 6, 2026
Signal K Server: Privilege Escalation by Admin Role Injection via /enableSecurity
Critical
CVE-2026-33950
was published
for
signalk-server
(npm)
Apr 3, 2026
Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)
Critical
GHSA-xg6x-h9c9-2m83
was published
for
better-auth
(npm)
Apr 3, 2026
mpp has multiple payment bypass and griefing vulnerabilities
Critical
GHSA-fxc9-7j2w-vx54
was published
for
mpp
(Rust)
Mar 29, 2026
mppx has multiple payment bypass and griefing vulnerabilities
Critical
GHSA-8x4m-qw58-3pcx
was published
for
mppx
(npm)
Mar 29, 2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobica Core...
Critical
Unreviewed
CVE-2026-27049
was published
Mar 25, 2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker /...
Critical
Unreviewed
CVE-2026-25035
was published
Mar 25, 2026
Mitigation bypass in the Networking: HTTP component. This vulnerability affects Firefox < 149 and...
Critical
Unreviewed
CVE-2026-4700
was published
Mar 24, 2026
An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages...
Critical
Unreviewed
CVE-2025-67039
was published
Mar 11, 2026
Authentication bypass issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to...
Critical
Unreviewed
CVE-2026-27842
was published
Mar 11, 2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes...
Critical
Unreviewed
CVE-2026-27389
was published
Mar 5, 2026
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software...
Critical
Unreviewed
CVE-2026-20079
was published
Mar 4, 2026
The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable...
Critical
Unreviewed
CVE-2026-2628
was published
Mar 3, 2026
FUXA has JWT Authentication Bypass via HTTP Referer header spoofing
Critical
CVE-2025-69985
was published
for
@frangoteam/fuxa
(npm)
Feb 24, 2026
ProTip!
Advisories are also available from the
GraphQL API