GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
576 advisories
Filter by severity
Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions.
High
Unreviewed
CVE-2026-73188
was published
Aug 13, 2026
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
Critical
Unreviewed
CVE-2026-66453
was published
Aug 13, 2026
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Critical
Unreviewed
CVE-2026-66465
was published
Aug 13, 2026
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager...
High
Unreviewed
CVE-2026-70468
was published
Aug 12, 2026
The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the...
Moderate
Unreviewed
CVE-2026-18636
was published
Aug 11, 2026
An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an...
High
Unreviewed
CVE-2026-72691
was published
Aug 10, 2026
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
High
CVE-2026-67309
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.
Moderate
Unreviewed
CVE-2026-66451
was published
Aug 6, 2026
Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form,...
Moderate
Unreviewed
CVE-2026-66425
was published
Aug 6, 2026
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
High
Unreviewed
CVE-2026-65542
was published
Aug 6, 2026
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an...
Critical
Unreviewed
CVE-2026-24254
was published
Aug 4, 2026
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to...
Critical
Unreviewed
CVE-2026-58073
was published
Aug 4, 2026
SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode...
Critical
Unreviewed
CVE-2026-68584
was published
Aug 3, 2026
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain...
Critical
Unreviewed
CVE-2026-18574
was published
Aug 3, 2026
A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated...
Critical
Unreviewed
CVE-2026-33591
was published
Aug 3, 2026
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N...
High
Unreviewed
CVE-2026-18577
was published
Aug 3, 2026
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows...
High
Unreviewed
CVE-2026-18556
was published
Aug 1, 2026
better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when...
High
Unreviewed
CVE-2026-67337
was published
Aug 1, 2026
A Spring Security authentication and authorization bypass exists in Coverity Connect versions...
Critical
Unreviewed
CVE-2026-8338
was published
Jul 29, 2026
TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error...
High
Unreviewed
CVE-2026-12703
was published
Jul 29, 2026
A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact...
Moderate
Unreviewed
CVE-2026-18047
was published
Jul 28, 2026
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin...
Critical
Unreviewed
CVE-2026-15014
was published
Jul 28, 2026
The web management interface of Tycon Systems TPDIN-Monitor-WEB2
does not perform server-side...
Critical
Unreviewed
CVE-2026-61884
was published
Jul 25, 2026
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
Moderate
Unreviewed
CVE-2026-59524
was published
Jul 23, 2026
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
High
Unreviewed
CVE-2026-59545
was published
Jul 23, 2026
ProTip!
Advisories are also available from the
GraphQL API