GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
275 advisories
Filter by severity
Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache...
High
Unreviewed
CVE-2026-73636
was published
Oct 1, 2026
MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that...
Critical
Unreviewed
CVE-2026-103655
was published
Oct 1, 2026
Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a...
High
Unreviewed
CVE-2026-82379
was published
Sep 28, 2026
http4k's Digest authentication module (org.http4k:http4k-security-digest) before versions 6.48.0...
High
Unreviewed
CVE-2026-100834
was published
Sep 27, 2026
The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately...
High
Unreviewed
CVE-2026-77967
was published
Sep 24, 2026
Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured...
High
Unreviewed
CVE-2026-87119
was published
Sep 22, 2026
mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing...
High
Unreviewed
CVE-2026-94112
was published
Sep 20, 2026
On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an...
Moderate
Unreviewed
CVE-2026-73443
was published
Sep 16, 2026
Http4s: DigestAuth allows replay of captured requests
Moderate
CVE-2026-69206
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse...
Critical
Unreviewed
CVE-2026-88278
was published
Sep 10, 2026
Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js...
High
Unreviewed
CVE-2026-84003
was published
Sep 8, 2026
Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to...
High
Unreviewed
CVE-2026-69676
was published
Sep 8, 2026
XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to...
Critical
Unreviewed
CVE-2026-73312
was published
Sep 8, 2026
XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows...
Critical
Unreviewed
CVE-2026-73311
was published
Sep 8, 2026
PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so...
Moderate
Unreviewed
CVE-2022-51016
was published
Sep 7, 2026
Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication...
Critical
Unreviewed
CVE-2026-86219
was published
Sep 6, 2026
When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation...
Moderate
Unreviewed
CVE-2026-12704
was published
Sep 2, 2026
Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used
Moderate
CVE-2026-84306
was published
for
filament/filament
(Composer)
Sep 1, 2026
Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp...
Moderate
Unreviewed
CVE-2026-82470
was published
Aug 29, 2026
Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.
Moderate
Unreviewed
CVE-2026-82220
was published
Aug 28, 2026
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a...
High
Unreviewed
CVE-2025-61479
was published
Aug 26, 2026
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a...
High
Unreviewed
CVE-2025-61480
was published
Aug 26, 2026
Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability....
High
Unreviewed
CVE-2026-41707
was published
Aug 26, 2026
Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability
Critical
CVE-2026-65905
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Aug 26, 2026
Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to...
Critical
Unreviewed
CVE-2026-53424
was published
Aug 20, 2026
ProTip!
Advisories are also available from the
GraphQL API