GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
2,042 advisories
Filter by severity
Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that...
High
Unreviewed
CVE-2026-65319
was published
Jul 22, 2026
SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc...
High
Unreviewed
CVE-2026-63757
was published
Jul 20, 2026
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The...
Critical
Unreviewed
CVE-2026-16242
was published
Jul 20, 2026
Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack Authentication
Moderate
CVE-2026-54246
was published
for
github.com/zalando/skipper
(Go)
Jul 17, 2026
IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication...
Critical
Unreviewed
CVE-2026-8505
was published
Jul 17, 2026
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access...
Critical
Unreviewed
CVE-2026-9103
was published
Jul 17, 2026
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user...
Critical
Unreviewed
CVE-2026-9202
was published
Jul 17, 2026
Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows...
High
Unreviewed
CVE-2026-63101
was published
Jul 17, 2026
Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video...
High
Unreviewed
CVE-2026-12691
was published
Jul 17, 2026
TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that...
Moderate
Unreviewed
CVE-2026-63098
was published
Jul 17, 2026
clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet...
Critical
Unreviewed
CVE-2026-62241
was published
Jul 17, 2026
EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46...
High
Unreviewed
CVE-2024-34268
was published
Jul 16, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode
High
CVE-2026-53714
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows...
Critical
Unreviewed
CVE-2026-63087
was published
Jul 16, 2026
During an internal security assessment, a potential improper access control vulnerability was...
Moderate
Unreviewed
CVE-2026-6511
was published
Jul 16, 2026
@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default
High
CVE-2026-54504
was published
for
@andrea9293/mcp-documentation-server
(npm)
Jul 15, 2026
GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information...
High
Unreviewed
CVE-2026-58658
was published
Jul 15, 2026
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could...
Critical
Unreviewed
CVE-2026-48325
was published
Jul 14, 2026
NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing...
Moderate
Unreviewed
CVE-2026-24259
was published
Jul 14, 2026
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator...
High
Unreviewed
CVE-2026-24229
was published
Jul 14, 2026
Adobe Experience Manager is affected by a Missing Authentication for Critical Function...
High
Unreviewed
CVE-2026-48252
was published
Jul 14, 2026
NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode
High
CVE-2026-54446
was published
for
netlicensing-mcp
(pip)
Jul 14, 2026
Missing authentication for critical function in Windows Server Update Service allows an...
High
Unreviewed
CVE-2026-50444
was published
Jul 14, 2026
Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS)...
High
Unreviewed
CVE-2026-50451
was published
Jul 14, 2026
Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to...
High
Unreviewed
CVE-2026-57969
was published
Jul 14, 2026
ProTip!
Advisories are also available from the
GraphQL API