GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
579 advisories
Filter by severity
Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH...
Critical
Unreviewed
CVE-2026-86462
was published
Sep 16, 2026
Apache Airflow FAB provider: resetting a user's password does not delete that user's existing...
Critical
Unreviewed
CVE-2026-82311
was published
Sep 16, 2026
A flaw was found in the first broker login flow of Keycloak. When a user confirms an account...
Moderate
Unreviewed
CVE-2026-92358
was published
Sep 16, 2026
Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass.
...
High
Unreviewed
CVE-2026-88262
was published
Sep 15, 2026
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
Moderate
CVE-2026-56665
was published
for
github.com/zitadel/zitadel
(Go)
Sep 11, 2026
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute...
High
Unreviewed
CVE-2026-81268
was published
Sep 11, 2026
Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
Moderate
CVE-2026-87014
was published
for
open-webui
(pip)
Sep 10, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
Moderate
Unreviewed
CVE-2026-80174
was published
Sep 9, 2026
A vulnerability was identified in Mstfakts College-Management-System. The affected element is an...
Low
Unreviewed
CVE-2026-86215
was published
Sep 6, 2026
WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php,...
Critical
Unreviewed
CVE-2026-84480
was published
Sep 2, 2026
Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their...
High
Unreviewed
CVE-2026-84203
was published
Sep 1, 2026
A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue...
Low
Unreviewed
CVE-2026-82909
was published
Aug 31, 2026
Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route...
Moderate
Unreviewed
CVE-2026-82469
was published
Aug 29, 2026
HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may...
Moderate
Unreviewed
CVE-2025-62342
was published
Aug 27, 2026
Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for...
Moderate
Unreviewed
CVE-2026-73180
was published
Aug 26, 2026
Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option,...
Critical
Unreviewed
CVE-2026-79664
was published
Aug 25, 2026
The extension fails to properly validate the expiration of a client-supplied JWT token, allowing...
Moderate
Unreviewed
CVE-2026-77130
was published
Aug 25, 2026
An unauthenticated remote attacker in possession of a valid session identifier is able to...
Critical
Unreviewed
CVE-2026-14950
was published
Aug 20, 2026
File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy...
High
Unreviewed
CVE-2026-73611
was published
Aug 13, 2026
Credentials for a deleted user may remain valid for a short period under specific conditions.
Moderate
Unreviewed
CVE-2026-66376
was published
Aug 12, 2026
Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke...
High
Unreviewed
CVE-2026-17600
was published
Aug 7, 2026
When internal roles are removed from a user within the WSO2 product, the system fails to...
Moderate
Unreviewed
CVE-2025-12317
was published
Aug 7, 2026
Unused authorization codes issued to deleted users are not being properly invalidated or removed...
Moderate
Unreviewed
CVE-2024-8995
was published
Aug 6, 2026
The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens...
Low
Unreviewed
CVE-2025-12627
was published
Aug 6, 2026
Insufficient Session Expiration vulnerability in Apache Answer.
This issue affects Apache Answer...
Critical
Unreviewed
CVE-2026-60053
was published
Aug 5, 2026
ProTip!
Advisories are also available from the
GraphQL API