GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
30 advisories
Filter by severity
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and...
Critical
Unreviewed
CVE-2026-61466
was published
Aug 6, 2026
Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was...
High
Unreviewed
CVE-2026-55957
was published
Jun 29, 2026
It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA...
High
Unreviewed
CVE-2026-57915
was published
Jun 26, 2026
Apache HttpClient accepts SCRAM-SHA-256 authentication without proper mutual authentication verification
High
CVE-2026-40542
was published
for
org.apache.httpcomponents.client5:httpclient5
(Maven)
Apr 22, 2026
Ray's New Token Authentication is Disabled By Default
Critical
CVE-2025-34351
was published
for
ray
(pip)
Nov 27, 2025
Liferay DXP Missing Critical Step in Authentication
Low
CVE-2025-43798
was published
for
com.liferay:com.liferay.multi.factor.authentication.timebased.otp.web
(Maven)
Sep 15, 2025
An unsafe default authentication vulnerability exists in the Initial Setup Authentication...
High
Unreviewed
CVE-2025-24322
was published
Aug 20, 2025
LinkJoin through 882f196 mishandles token ownership in password reset.
High
Unreviewed
CVE-2025-55138
was published
Aug 7, 2025
A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6...
High
Unreviewed
CVE-2024-52965
was published
Jul 8, 2025
A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic....
Low
Unreviewed
CVE-2025-5715
was published
Jun 6, 2025
In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient...
Moderate
Unreviewed
CVE-2025-43014
was published
Apr 17, 2025
A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows...
High
Unreviewed
CVE-2024-9919
was published
Mar 20, 2025
An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f...
High
Unreviewed
CVE-2024-9216
was published
Mar 20, 2025
In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value...
Critical
Unreviewed
CVE-2024-8954
was published
Mar 20, 2025
A missing check_access() function in the lollms_binding_infos module of the parisneo/lollms...
High
Unreviewed
CVE-2024-11302
was published
Mar 20, 2025
An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi...
High
Unreviewed
CVE-2024-12048
was published
Mar 20, 2025
Missing Critical Step in Authentication vulnerability in Elfatek Elektronics ANKA JPD-00028...
Moderate
Unreviewed
CVE-2024-12136
was published
Mar 19, 2025
In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID....
High
Unreviewed
CVE-2024-20153
was published
Jan 6, 2025
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in...
Critical
Unreviewed
CVE-2024-45764
was published
Nov 8, 2024
In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id...
Moderate
Unreviewed
CVE-2024-6040
was published
Aug 1, 2024
The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an...
High
Unreviewed
CVE-2023-52424
was published
May 17, 2024
The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by...
Critical
Unreviewed
CVE-2024-2172
was published
Mar 13, 2024
Armeria SAML authentication bypass due to missing validation on unsigned SAML messages
Critical
CVE-2024-1735
was published
for
com.linecorp.armeria:armeria-saml
(Maven)
Feb 26, 2024
Infinispan REST Server's bulk read endpoints do not properly evaluate user permissions
High
CVE-2023-3628
was published
for
org.infinispan:infinispan-server-rest
(Maven)
Dec 30, 2023
Infinispan REST Server's cache retrieval endpoints do not properly evaluate the necessary admin permissions
High
CVE-2023-3629
was published
for
org.infinispan:infinispan-server-rest
(Maven)
Dec 30, 2023
ProTip!
Advisories are also available from the
GraphQL API