GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
812 advisories
Filter by severity
In multiple locations, there is a possible improper encryption key validation due to a logic...
High
Unreviewed
CVE-2026-28590
was published
Sep 8, 2026
Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized...
High
Unreviewed
CVE-2026-57098
was published
Sep 8, 2026
CommServe contained a cryptographic signature verification issue affecting privilege management....
High
Unreviewed
CVE-2026-77105
was published
Sep 8, 2026
When using the Direct XIP
update strategy, the main application image starts other cores (i.e....
High
Unreviewed
CVE-2026-14296
was published
Sep 7, 2026
MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because...
Critical
Unreviewed
CVE-2026-86304
was published
Sep 7, 2026
MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because...
Moderate
Unreviewed
CVE-2026-67278
was published
Sep 5, 2026
RouterOS does not compare the complete RSA public key when matching an SSH authentication request...
Critical
Unreviewed
CVE-2026-67276
was published
Sep 5, 2026
Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT command processing. An...
High
Unreviewed
CVE-2026-79389
was published
Sep 4, 2026
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized...
Critical
Unreviewed
CVE-2026-80098
was published
Sep 4, 2026
node-forge RSA PKCS#1 v1.5 signature verification accepts extra nested DigestAlgorithm elements
High
CVE-2026-85393
was published
for
node-forge
(npm)
Sep 3, 2026
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization,...
Critical
Unreviewed
CVE-2026-85394
was published
Sep 3, 2026
A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3)...
High
Unreviewed
CVE-2026-80465
was published
Sep 3, 2026
A signature verification bypass vulnerability exists in the command line interface of AOS-CX....
High
Unreviewed
CVE-2026-73776
was published
Sep 1, 2026
Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded...
Critical
Unreviewed
CVE-2026-82876
was published
Aug 31, 2026
AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live...
Critical
Unreviewed
CVE-2026-82645
was published
Aug 30, 2026
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry...
High
Unreviewed
CVE-2026-82461
was published
Aug 29, 2026
The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication...
Critical
Unreviewed
CVE-2026-82454
was published
Aug 29, 2026
AIIR verification and policy gates could report success without enforcing the control (fail-open)
Moderate
GHSA-73p9-6hrp-8qhr
was published
for
aiir
(pip)
Aug 28, 2026
Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel)
High
CVE-2026-54736
was published
for
phalcon/cphalcon
(Composer)
Aug 28, 2026
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all...
Critical
Unreviewed
CVE-2026-76581
was published
Aug 28, 2026
openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the...
Critical
Unreviewed
CVE-2026-81717
was published
Aug 27, 2026
openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching...
Critical
Unreviewed
CVE-2026-81714
was published
Aug 27, 2026
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in...
Critical
Unreviewed
CVE-2026-81700
was published
Aug 27, 2026
openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins,...
Critical
Unreviewed
CVE-2026-81701
was published
Aug 27, 2026
openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope...
Critical
Unreviewed
CVE-2026-81680
was published
Aug 27, 2026
ProTip!
Advisories are also available from the
GraphQL API