GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,169
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
28 advisories
Filter by severity
When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted...
High
Unreviewed
CVE-2026-56091
was published
Jun 25, 2026
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of...
Critical
Unreviewed
CVE-2026-50627
was published
Jun 12, 2026
Go-tuf Improperly handles multiple key IDs for the same public keys in attacker-controlled metadata
Low
GHSA-3633-5h82-39pq
was published
for
github.com/theupdateframework/go-tuf
(Go)
Sep 16, 2022
Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's...
Moderate
Unreviewed
CVE-2026-43617
was published
May 20, 2026
A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility,...
Low
Unreviewed
CVE-2026-3184
was published
Apr 3, 2026
The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an...
High
Unreviewed
CVE-2024-2098
was published
Jun 13, 2024
OpenClaw's MS Teams sender allowlist bypass when route allowlist is configured and sender allowlist is empty
Moderate
CVE-2026-34506
was published
for
openclaw
(npm)
Mar 12, 2026
A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerability exists in the admin...
Moderate
Unreviewed
CVE-2025-14777
was published
Dec 16, 2025
OpenClaw has gateway plugin auth bypass via encoded dot-segment traversal in protected /api/channels paths
High
CVE-2026-32036
was published
for
openclaw
(npm)
Mar 3, 2026
Apache Shiro has an Authentication Bypass
Moderate
CVE-2026-23903
was published
for
org.apache.shiro:shiro-spring
(Maven)
Feb 9, 2026
Soft Serve Affected by an Authentication Bypass
High
CVE-2026-24058
was published
for
github.com/charmbracelet/soft-serve
(Go)
Jan 21, 2026
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow...
High
Unreviewed
CVE-2025-55130
was published
Jan 20, 2026
A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network...
Moderate
Unreviewed
CVE-2025-8415
was published
Aug 20, 2025
The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions...
Critical
Unreviewed
CVE-2025-13613
was published
Dec 10, 2025
authentik allows a deactivated Service account to authenticate to OAuth
Moderate
CVE-2025-64521
was published
for
goauthentik.io
(Go)
Nov 19, 2025
The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login...
High
Unreviewed
CVE-2025-60375
was published
Oct 9, 2025
Spring Security annotation detection mechanism has authorization bypass
High
CVE-2025-41248
was published
for
org.springframework.security:spring-security-core
(Maven)
Sep 16, 2025
Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root...
Critical
Unreviewed
CVE-2025-29266
was published
Mar 31, 2025
The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to,...
High
Unreviewed
CVE-2024-11283
was published
Mar 14, 2025
Hail relies on OIDC email claims to verify the validity of a user's domain.
Moderate
CVE-2023-51663
was published
for
hail
(pip)
Jan 2, 2024
Moodle Lesson activity password bypass through PHP loose comparison
Moderate
CVE-2024-45691
was published
for
moodle/moodle
(Composer)
Nov 20, 2024
Symfony has an Authentication Bypass via RememberMe
High
CVE-2024-51996
was published
for
symfony/security-http
(Composer)
Nov 13, 2024
Missing key verification in gost
Critical
CVE-2024-39223
was published
for
github.com/ginuerzh/gost
(Go)
Jul 3, 2024
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
High
CVE-2023-41890
was published
for
Kentor.AuthServices
(NuGet)
Sep 20, 2023
Avantra Server 24.x before 24.0.7 and 24.1.x before 24.1.1 mishandles the security of dashboards,...
Moderate
Unreviewed
CVE-2024-34519
was published
May 6, 2024
ProTip!
Advisories are also available from the
GraphQL API