GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
251 advisories
Filter by severity
Mitigation bypass in the DOM: Security component. This vulnerability affects Firefox < 148 and...
Critical
Unreviewed
CVE-2026-2784
was published
Feb 24, 2026
Mitigation bypass in the Networking: Cache component. This vulnerability affects Firefox < 148...
Critical
Unreviewed
CVE-2026-2791
was published
Feb 24, 2026
Mitigation bypass in the DOM: HTML Parser component. This vulnerability affects Firefox < 148,...
Critical
Unreviewed
CVE-2026-2775
was published
Feb 24, 2026
Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing...
Critical
Unreviewed
CVE-2026-2095
was published
Feb 10, 2026
Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing...
Critical
Unreviewed
CVE-2026-2096
was published
Feb 10, 2026
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability...
Critical
Unreviewed
CVE-2026-24858
was published
Jan 27, 2026
An Authentication Bypass Using an
Alternate Path or Channel vulnerability in Juniper Networks...
Critical
Unreviewed
CVE-2025-21589
was published
Jan 27, 2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Workreap...
Critical
Unreviewed
CVE-2025-69101
was published
Jan 22, 2026
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass...
Critical
Unreviewed
CVE-2026-23760
was published
Jan 22, 2026
The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is...
Critical
Unreviewed
CVE-2025-10484
was published
Jan 17, 2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan...
Critical
Unreviewed
CVE-2025-23504
was published
Jan 8, 2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Arraytics Timetics...
Critical
Unreviewed
CVE-2025-67915
was published
Jan 8, 2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Nuvation Energy Multi...
Critical
Unreviewed
CVE-2025-64121
was published
Jan 3, 2026
Signal K Server vulnerable to JWT Token Theft via WebSocket Enumeration and Unauthenticated Polling
Critical
CVE-2025-68620
was published
for
signalk-server
(npm)
Jan 2, 2026
DVP-12SE11T - Password Protection Bypass
Critical
Unreviewed
CVE-2025-15102
was published
Dec 30, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Mobile Builder Mobile...
Critical
Unreviewed
CVE-2025-68860
was published
Dec 30, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn...
Critical
Unreviewed
CVE-2025-64236
was published
Dec 18, 2025
The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all...
Critical
Unreviewed
CVE-2025-13539
was published
Nov 27, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in ABB ABB Ability...
Critical
Unreviewed
CVE-2025-10571
was published
Nov 20, 2025
The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper...
Critical
Unreviewed
CVE-2025-63217
was published
Nov 19, 2025
An authentication bypass vulnerability has been identified in certain DSL series routers, may...
Critical
Unreviewed
CVE-2025-59367
was published
Nov 13, 2025
An Authentication Bypass issue in CentralSquare Community Development 19.5.7 allows attackers to...
Critical
Unreviewed
CVE-2025-64281
was published
Nov 12, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Elated-Themes Search &...
Critical
Unreviewed
CVE-2025-62064
was published
Nov 6, 2025
The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up...
Critical
Unreviewed
CVE-2025-5397
was published
Oct 31, 2025
An unauthenticated user can connect to a publicly accessible database using arbitrary credentials...
Critical
Unreviewed
CVE-2025-9313
was published
Oct 28, 2025
ProTip!
Advisories are also available from the
GraphQL API