GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
49 advisories
Filter by severity
Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows...
Critical
Unreviewed
CVE-2026-73683
was published
Aug 15, 2026
Craft CMS: Passkey login accepts replayed WebAuthn assertions
Critical
GHSA-wg23-69c2-gjc8
was published
for
craftcms/cms
(Composer)
Aug 7, 2026
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed...
Critical
Unreviewed
CVE-2026-68079
was published
Aug 6, 2026
Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache...
Critical
Unreviewed
CVE-2026-28564
was published
Jul 10, 2026
MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in...
Critical
Unreviewed
CVE-2026-51597
was published
Jul 9, 2026
When reusing a libcurl handle for sequential transfers driven by
environment-variable proxy...
Critical
Unreviewed
CVE-2026-8927
was published
Jul 3, 2026
Successfully using libcurl to do a transfer to a specific HTTP origin
(`hostA`) with **Digest**...
Critical
Unreviewed
CVE-2026-11856
was published
Jul 3, 2026
Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and...
Critical
Unreviewed
CVE-2026-26232
was published
Jul 3, 2026
Authentication Bypass by Capture-replay, Use of Password Hash With Insufficient Computational...
Critical
Unreviewed
CVE-2026-30789
was published
Mar 5, 2026
An Authentication Bypass by Capture-Replay issue was discovered in Schneider Electric Modicon...
Critical
Unreviewed
CVE-2017-6034
was published
May 13, 2022
An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product...
Critical
Unreviewed
CVE-2018-7790
was published
May 13, 2022
OpenClaw: Feishu webhook and card-action validation now fail closed
Critical
CVE-2026-44109
was published
for
openclaw
(npm)
Apr 17, 2026
mpp has multiple payment bypass and griefing vulnerabilities
Critical
GHSA-fxc9-7j2w-vx54
was published
for
mpp
(Rust)
Mar 29, 2026
OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing...
Critical
Unreviewed
CVE-2026-32987
was published
Mar 29, 2026
mppx has multiple payment bypass and griefing vulnerabilities
Critical
GHSA-8x4m-qw58-3pcx
was published
for
mppx
(npm)
Mar 29, 2026
Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to...
Critical
Unreviewed
CVE-2025-67135
was published
Feb 12, 2026
D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz...
Critical
Unreviewed
CVE-2025-65552
was published
Jan 12, 2026
Azure Bastion Elevation of Privilege Vulnerability
Critical
Unreviewed
CVE-2025-49752
was published
Nov 21, 2025
Microsoft Outlook Elevation of Privilege Vulnerability
Critical
Unreviewed
CVE-2023-23397
was published
Mar 14, 2023
Taylored webhook validation vulnerabilities
Critical
GHSA-8g98-m4j9-qww5
was published
for
taylored
(npm)
Jun 18, 2025
Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key...
Critical
Unreviewed
CVE-2025-6029
was published
Jun 13, 2025
Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key...
Critical
Unreviewed
CVE-2025-6030
was published
Jun 13, 2025
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to...
Critical
Unreviewed
CVE-2017-3191
was published
May 13, 2022
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force...
Critical
Unreviewed
CVE-2021-22640
was published
Jul 29, 2022
A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix ...
Critical
Unreviewed
CVE-2021-27289
was published
Apr 15, 2025
ProTip!
Advisories are also available from the
GraphQL API