GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,865
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,587
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
713 advisories
Filter by severity
User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate...
High
Unreviewed
CVE-2026-104733
was published
Oct 2, 2026
YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox...
High
Unreviewed
CVE-2026-104445
was published
Oct 2, 2026
Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions.
Moderate
Unreviewed
CVE-2026-103347
was published
Oct 1, 2026
OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing...
Moderate
Unreviewed
CVE-2026-103397
was published
Sep 30, 2026
Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.
Critical
Unreviewed
CVE-2026-97274
was published
Sep 30, 2026
Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions.
Moderate
Unreviewed
CVE-2026-97249
was published
Sep 30, 2026
Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions.
Moderate
Unreviewed
CVE-2026-96825
was published
Sep 30, 2026
Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be...
Moderate
Unreviewed
CVE-2026-92899
was published
Sep 30, 2026
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field...
Critical
Unreviewed
CVE-2026-100390
was published
Sep 25, 2026
An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway...
Moderate
Unreviewed
CVE-2026-94416
was published
Sep 24, 2026
Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
Moderate
Unreviewed
CVE-2026-95524
was published
Sep 23, 2026
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
Moderate
Unreviewed
CVE-2026-95523
was published
Sep 23, 2026
Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions.
Moderate
Unreviewed
CVE-2026-94457
was published
Sep 23, 2026
TarsWeb decides whether a request comes from a trusted local caller using a client-controlled...
Critical
Unreviewed
CVE-2026-80349
was published
Sep 23, 2026
9router /v1 APIs has unauthenticated access via reverse proxy locality collapse
High
CVE-2026-56675
was published
for
9router
(npm)
Sep 23, 2026
The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature...
Moderate
Unreviewed
CVE-2026-93511
was published
Sep 23, 2026
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header...
Moderate
Unreviewed
CVE-2026-92929
was published
Sep 23, 2026
Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header
Moderate
CVE-2026-62987
was published
for
github.com/fabiolb/fabio
(Go)
Sep 22, 2026
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace
Critical
CVE-2026-61682
was published
for
github.com/kcp-dev/kcp
(Go)
Sep 18, 2026
A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an...
Moderate
Unreviewed
CVE-2026-85511
was published
Sep 18, 2026
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate...
Critical
Unreviewed
CVE-2026-69843
was published
Sep 18, 2026
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to...
Critical
Unreviewed
CVE-2026-77903
was published
Sep 18, 2026
pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web...
Critical
Unreviewed
CVE-2026-86863
was published
Sep 17, 2026
libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses
High
CVE-2026-86039
was published
for
@libp2p/peer-store
(npm)
Sep 17, 2026
Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.
Critical
Unreviewed
CVE-2026-62108
was published
Sep 17, 2026
ProTip!
Advisories are also available from the
GraphQL API