GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
251 advisories
Filter by severity
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Critical
Unreviewed
CVE-2026-66465
was published
Aug 13, 2026
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
Critical
Unreviewed
CVE-2026-66453
was published
Aug 13, 2026
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an...
Critical
Unreviewed
CVE-2026-24254
was published
Aug 4, 2026
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to...
Critical
Unreviewed
CVE-2026-58073
was published
Aug 4, 2026
SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode...
Critical
Unreviewed
CVE-2026-68584
was published
Aug 3, 2026
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain...
Critical
Unreviewed
CVE-2026-18574
was published
Aug 3, 2026
A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated...
Critical
Unreviewed
CVE-2026-33591
was published
Aug 3, 2026
A Spring Security authentication and authorization bypass exists in Coverity Connect versions...
Critical
Unreviewed
CVE-2026-8338
was published
Jul 29, 2026
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin...
Critical
Unreviewed
CVE-2026-15014
was published
Jul 28, 2026
The web management interface of Tycon Systems TPDIN-Monitor-WEB2
does not perform server-side...
Critical
Unreviewed
CVE-2026-61884
was published
Jul 25, 2026
The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full...
Critical
Unreviewed
CVE-2026-61425
was published
Jul 20, 2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security...
Critical
Unreviewed
CVE-2026-57807
was published
Jul 10, 2026
An authentication bypass vulnerability exists in
the default SFTP server component utilized...
Critical
Unreviewed
CVE-2026-5268
was published
Jul 6, 2026
Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability...
Critical
Unreviewed
CVE-2026-58172
was published
Jun 30, 2026
Mitigation bypass in the Networking: HTTP component. This vulnerability affects Firefox < 149 and...
Critical
Unreviewed
CVE-2026-4700
was published
Mar 24, 2026
Mitigation bypass in the DOM: HTML Parser component. This vulnerability affects Firefox < 148,...
Critical
Unreviewed
CVE-2026-2775
was published
Feb 24, 2026
WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass...
Critical
Unreviewed
CVE-2019-25763
was published
Jun 20, 2026
Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.
Critical
Unreviewed
CVE-2026-49767
was published
Jun 17, 2026
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.
Critical
Unreviewed
CVE-2026-49764
was published
Jun 15, 2026
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and...
Critical
Unreviewed
CVE-2026-10523
was published
Jun 9, 2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in GST Electronics inohom...
Critical
Unreviewed
CVE-2024-6684
was published
Aug 12, 2024
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON...
Critical
Unreviewed
CVE-2018-8859
was published
May 13, 2022
Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or...
Critical
Unreviewed
CVE-2025-41273
was published
May 29, 2026
In Slican telephone exchanges it is possible to manage the control panel remotely. An...
Critical
Unreviewed
CVE-2026-35090
was published
May 27, 2026
Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can...
Critical
Unreviewed
CVE-2026-35087
was published
May 27, 2026
ProTip!
Advisories are also available from the
GraphQL API