GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
34 advisories
Filter by severity
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all...
Critical
Unreviewed
CVE-2026-8457
was published
Aug 2, 2026
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0...
High
Unreviewed
CVE-2026-10842
was published
Jul 30, 2026
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all...
Critical
Unreviewed
CVE-2026-9701
was published
Jul 8, 2026
Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
High
CVE-2026-55075
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead...
High
Unreviewed
CVE-2026-48618
was published
Jun 26, 2026
When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted...
High
Unreviewed
CVE-2026-56091
was published
Jun 25, 2026
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of...
Critical
Unreviewed
CVE-2026-50627
was published
Jun 12, 2026
axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
High
CVE-2026-44492
was published
for
axios
(npm)
May 29, 2026
Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's...
Moderate
Unreviewed
CVE-2026-43617
was published
May 20, 2026
A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility,...
Low
Unreviewed
CVE-2026-3184
was published
Apr 3, 2026
OpenClaw's MS Teams sender allowlist bypass when route allowlist is configured and sender allowlist is empty
Moderate
CVE-2026-34506
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw has gateway plugin auth bypass via encoded dot-segment traversal in protected /api/channels paths
High
CVE-2026-32036
was published
for
openclaw
(npm)
Mar 3, 2026
Apache Shiro has an Authentication Bypass
Moderate
CVE-2026-23903
was published
for
org.apache.shiro:shiro-spring
(Maven)
Feb 9, 2026
Soft Serve Affected by an Authentication Bypass
High
CVE-2026-24058
was published
for
github.com/charmbracelet/soft-serve
(Go)
Jan 21, 2026
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow...
High
Unreviewed
CVE-2025-55130
was published
Jan 20, 2026
A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerability exists in the admin...
Moderate
Unreviewed
CVE-2025-14777
was published
Dec 16, 2025
The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions...
Critical
Unreviewed
CVE-2025-13613
was published
Dec 10, 2025
authentik allows a deactivated Service account to authenticate to OAuth
Moderate
CVE-2025-64521
was published
for
goauthentik.io
(Go)
Nov 19, 2025
The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login...
High
Unreviewed
CVE-2025-60375
was published
Oct 9, 2025
Spring Security annotation detection mechanism has authorization bypass
High
CVE-2025-41248
was published
for
org.springframework.security:spring-security-core
(Maven)
Sep 16, 2025
A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network...
Moderate
Unreviewed
CVE-2025-8415
was published
Aug 20, 2025
Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root...
Critical
Unreviewed
CVE-2025-29266
was published
Mar 31, 2025
The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to,...
High
Unreviewed
CVE-2024-11283
was published
Mar 14, 2025
Moodle Lesson activity password bypass through PHP loose comparison
Moderate
CVE-2024-45691
was published
for
moodle/moodle
(Composer)
Nov 20, 2024
Symfony has an Authentication Bypass via RememberMe
High
CVE-2024-51996
was published
for
symfony/security-http
(Composer)
Nov 13, 2024
ProTip!
Advisories are also available from the
GraphQL API