GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
275 advisories
Filter by severity
Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to...
High
Unreviewed
CVE-2026-73136
was published
Aug 19, 2026
Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to...
High
Unreviewed
CVE-2026-67581
was published
Aug 19, 2026
phpMyFAQ before 4.1.7 (affected versions <= 4.1.5) fails to persist the WebAuthn login challenge...
Critical
Unreviewed
CVE-2026-76214
was published
Aug 19, 2026
http4k: `DigestAuthProvider.verify` did not bind to request URI
High
CVE-2026-54148
was published
for
org.http4k:http4k-security-digest
(Maven)
Aug 17, 2026
Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows...
Critical
Unreviewed
CVE-2026-73683
was published
Aug 15, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized...
High
Unreviewed
CVE-2026-17045
was published
Aug 13, 2026
ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
Moderate
CVE-2026-55088
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security...
Moderate
Unreviewed
CVE-2026-17268
was published
Aug 12, 2026
Vulnerability-Lookup contains an
authentication weakness in its account activation and password...
High
Unreviewed
CVE-2026-73431
was published
Aug 12, 2026
nimiq-blockchain: Validity store off by one error
High
CVE-2026-46369
was published
for
nimiq-blockchain
(Rust)
Aug 12, 2026
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized...
High
Unreviewed
CVE-2026-62911
was published
Aug 11, 2026
Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion...
High
Unreviewed
CVE-2026-72780
was published
Aug 11, 2026
Craft CMS: Passkey login accepts replayed WebAuthn assertions
Critical
GHSA-wg23-69c2-gjc8
was published
for
craftcms/cms
(Composer)
Aug 7, 2026
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed...
Critical
Unreviewed
CVE-2026-68079
was published
Aug 6, 2026
A flaw was found in the SAML broker component of Keycloak, an identity and access management...
Moderate
Unreviewed
CVE-2026-18967
was published
Aug 6, 2026
Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse...
High
Unreviewed
CVE-2026-15614
was published
Jul 23, 2026
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface
High
CVE-2026-20779
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A...
Moderate
Unreviewed
CVE-2026-56453
was published
Jul 16, 2026
HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a...
Low
Unreviewed
CVE-2026-35141
was published
Jul 16, 2026
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response...
High
Unreviewed
CVE-2026-35149
was published
Jul 16, 2026
Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache...
Critical
Unreviewed
CVE-2026-28564
was published
Jul 10, 2026
MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in...
Critical
Unreviewed
CVE-2026-51597
was published
Jul 9, 2026
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
High
CVE-2026-53518
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
High
CVE-2026-53517
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
Gitea OAuth2 authorization codes can be reused after expiry
Critical
CVE-2026-26232
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
ProTip!
Advisories are also available from the
GraphQL API