GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
104 advisories
Filter by severity
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized...
High
Unreviewed
CVE-2026-17045
was published
Aug 13, 2026
Vulnerability-Lookup contains an
authentication weakness in its account activation and password...
High
Unreviewed
CVE-2026-73431
was published
Aug 12, 2026
nimiq-blockchain: Validity store off by one error
High
CVE-2026-46369
was published
for
nimiq-blockchain
(Rust)
Aug 12, 2026
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized...
High
Unreviewed
CVE-2026-62911
was published
Aug 11, 2026
Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion...
High
Unreviewed
CVE-2026-72780
was published
Aug 11, 2026
Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse...
High
Unreviewed
CVE-2026-15614
was published
Jul 23, 2026
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface
High
CVE-2026-20779
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response...
High
Unreviewed
CVE-2026-35149
was published
Jul 16, 2026
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
High
CVE-2026-53518
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
High
CVE-2026-53517
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages
High
CVE-2026-54783
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485...
High
Unreviewed
CVE-2026-34021
was published
Jun 15, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token
High
CVE-2026-45720
was published
for
github.com/siderolabs/omni
(Go)
Jun 5, 2026
Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay...
High
Unreviewed
CVE-2026-9095
was published
May 28, 2026
opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay
High
CVE-2026-42602
was published
for
github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension
(Go)
May 6, 2026
Duplicate Advisory: OpenClaw: Plivo V2 verified replay identity drifts on query-only variants
High
GHSA-j56c-wpqm-h24x
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection....
High
Unreviewed
CVE-2026-30080
was published
Apr 8, 2026
OpenClaw: Voice-call Plivo V3 webhook replay key uses unsorted URL, allowing replay via query-parameter reordering
High
CVE-2026-41395
was published
for
openclaw
(npm)
Mar 31, 2026
mppx: Tempo has a session close voucher bypass vulnerability due to settled amount equality
High
CVE-2026-34209
was published
for
mppx
(npm)
Mar 29, 2026
OpenClaw: Plivo V2 verified replay identity drifts on query-only variants
High
CVE-2026-35618
was published
for
openclaw
(npm)
Mar 26, 2026
Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote...
High
Unreviewed
CVE-2026-20999
was published
Mar 16, 2026
Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120...
High
Unreviewed
CVE-2025-13777
was published
Mar 13, 2026
OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replay
High
CVE-2026-28787
was published
for
@oneuptime/common
(npm)
Mar 2, 2026
Crafted delegations or IP fragments can poison cached delegations in Recursor.
High
Unreviewed
CVE-2025-59023
was published
Feb 9, 2026
Jenkins SAML Plugin does not implement a replay cache
High
CVE-2025-64131
was published
for
org.jenkins-ci.plugins:saml
(Maven)
Oct 29, 2025
ProTip!
Advisories are also available from the
GraphQL API