GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
4,585 advisories
Filter by severity
A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts...
Moderate
Unreviewed
CVE-2026-74240
was published
Aug 15, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
Moderate
Unreviewed
CVE-2026-16905
was published
Aug 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and...
Critical
Unreviewed
CVE-2026-17182
was published
Aug 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
High
Unreviewed
CVE-2026-17175
was published
Aug 14, 2026
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
High
CVE-2026-35511
was published
for
github.com/authorizerdev/authorizer
(Go)
Aug 14, 2026
The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a...
Moderate
Unreviewed
CVE-2026-16739
was published
Aug 14, 2026
A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C,...
Low
Unreviewed
CVE-2026-19749
was published
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to...
High
Unreviewed
CVE-2026-17099
was published
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and...
Moderate
Unreviewed
CVE-2026-17075
was published
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain...
High
Unreviewed
CVE-2026-17101
was published
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the...
High
Unreviewed
CVE-2026-16867
was published
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to...
High
Unreviewed
CVE-2026-17197
was published
Aug 13, 2026
The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly...
Critical
Unreviewed
CVE-2026-14182
was published
Aug 13, 2026
IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass...
Critical
Unreviewed
CVE-2024-27253
was published
Aug 13, 2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0...
High
Unreviewed
CVE-2026-11923
was published
Aug 12, 2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0...
High
Unreviewed
CVE-2026-12359
was published
Aug 12, 2026
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when...
High
Unreviewed
CVE-2026-42018
was published
Aug 12, 2026
An unauthenticated user may bypass authentication under specific cache conditions.
Moderate
Unreviewed
CVE-2026-68760
was published
Aug 12, 2026
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0...
Critical
Unreviewed
CVE-2026-26035
was published
Aug 12, 2026
The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin...
High
Unreviewed
CVE-2026-18961
was published
Aug 12, 2026
A flaw was found in search-v2-api. The authentication middleware in the affected component...
High
Unreviewed
CVE-2026-71467
was published
Aug 11, 2026
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-62827
was published
Aug 11, 2026
Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0:...
High
Unreviewed
CVE-2026-20885
was published
Aug 11, 2026
Improper authentication for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2...
Moderate
Unreviewed
CVE-2026-20891
was published
Aug 11, 2026
ProTip!
Advisories are also available from the
GraphQL API