GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,967
Maven
5,000+
npm
5,000+
NuGet
973
pip
5,000+
Pub
13
RubyGems
1,064
Rust
1,387
Swift
56
Unreviewed advisories
All unreviewed
5,000+
238 advisories
Filter by severity
Keylime Missing Authentication for Critical Function and Improper Authentication
Critical
CVE-2026-1709
was published
for
keylime
(pip)
Feb 6, 2026
Synapse's unauthenticated writes to the media repository allow planting of problematic content
Moderate
CVE-2024-37303
was published
for
matrix-synapse
(pip)
Dec 3, 2024
epa4all-client: Unauthenticated REST API for Patient Record Writes
Moderate
CVE-2026-47672
was published
for
com.oviva.telematik:epa4all-rest-service
(Maven)
Jun 4, 2026
Nhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secrets
Moderate
CVE-2026-47671
was published
for
github.com/nhost/nhost
(Go)
Jun 4, 2026
@agenticmail/mcp Missing Authentication for Critical Function
High
GHSA-63gr-g7jc-v8rg
was published
for
@agenticmail/mcp
(npm)
Jun 1, 2026
PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution
Critical
CVE-2026-47391
was published
for
PraisonAI
(pip)
May 29, 2026
PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
Critical
CVE-2026-47393
was published
for
PraisonAI
(pip)
May 29, 2026
PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset
Critical
CVE-2026-47396
was published
for
PraisonAI
(pip)
May 29, 2026
Symfony: Twilio SMS Notifier allows unauthenticated webhook injection due to missing X-Twilio-Signature verification
Moderate
CVE-2026-47212
was published
for
symfony/symfony
(Composer)
May 29, 2026
Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection
Moderate
CVE-2026-47122
was published
for
github.com/sparkle-project/Sparkle
(Swift)
May 29, 2026
mem0 server lacks authentication and authorization controls for its memory management API endpoints
High
CVE-2026-31240
was published
for
mem0ai
(pip)
May 12, 2026
Symfony's Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection
Moderate
CVE-2026-45755
was published
for
symfony/mailtrap-mailer
(Composer)
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Moderate
CVE-2026-45754
was published
for
symfony/lox24-notifier
(Composer)
May 28, 2026
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
Moderate
CVE-2026-31245
was published
for
mem0ai
(pip)
May 12, 2026
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
Moderate
CVE-2026-31241
was published
for
mem0ai
(pip)
May 12, 2026
Automad has Broken Access Control: Unauthenticated exposure of administrator bcrypt password hashes and TOTP secrets via public API endpoint
High
CVE-2026-45332
was published
for
automad/automad
(Composer)
May 27, 2026
Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives
High
CVE-2026-46612
was published
for
github.com/fission/fission
(Go)
May 21, 2026
Windows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORS
High
GHSA-vrxg-gm77-7q5g
was published
for
windows-mcp
(pip)
May 21, 2026
electerm allows unauthorized users to execute arbitrary commands
Critical
CVE-2020-23256
was published
for
electerm
(npm)
Jan 20, 2023
OpenClaude Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input
Critical
CVE-2026-42074
was published
for
openclaude
(npm)
May 12, 2026
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
Critical
CVE-2026-41179
was published
for
github.com/rclone/rclone
(Go)
Apr 22, 2026
Keycloak: Unauthorized authentication via disabled SAML Identity Provider
High
CVE-2026-2603
was published
for
org.keycloak:keycloak-server-spi-private
(Maven)
Mar 18, 2026
CamoFox MCP: Unauthenticated HTTP MCP browser-control surface
High
GHSA-7hgr-7h44-33w2
was published
for
camofox-mcp
(npm)
May 19, 2026
9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
Critical
CVE-2026-46339
was published
for
9router
(npm)
May 19, 2026
Kopia: RCE via SSH ProxyCommand Injection
Critical
CVE-2026-45695
was published
for
github.com/kopia/kopia
(Go)
May 19, 2026
ProTip!
Advisories are also available from the
GraphQL API