GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
546 advisories
Filter by severity
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access...
Critical
Unreviewed
CVE-2026-19297
was published
Aug 13, 2026
HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation...
Moderate
Unreviewed
CVE-2025-62314
was published
Aug 13, 2026
The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP...
Moderate
Unreviewed
CVE-2026-66340
was published
Aug 12, 2026
UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.
Note: UnixAuth is NOT...
High
Unreviewed
CVE-2026-65948
was published
Aug 10, 2026
The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second...
High
Unreviewed
CVE-2026-16619
was published
Aug 7, 2026
changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC...
Moderate
Unreviewed
CVE-2026-71205
was published
Aug 5, 2026
Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) performs no rate-limiting,...
Critical
Unreviewed
CVE-2026-71213
was published
Aug 5, 2026
PaperCut NG/MF does not properly restrict excessive authentication attempts within its login...
Moderate
Unreviewed
CVE-2026-8793
was published
Aug 3, 2026
InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is...
Moderate
Unreviewed
CVE-2021-29023
was published
May 24, 2022
MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective...
High
Unreviewed
CVE-2026-16347
was published
Jul 28, 2026
Successful exploitation of this vulnerability
could allow an attacker with local network access...
Low
Unreviewed
CVE-2026-55977
was published
Jul 28, 2026
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP...
High
Unreviewed
CVE-2026-65894
was published
Jul 27, 2026
Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc...
Moderate
Unreviewed
CVE-2026-8285
was published
Jul 21, 2026
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user...
High
Unreviewed
CVE-2026-3329
was published
Jun 11, 2026
NocoDB: User Enumeration via Sign-In Timing
Moderate
CVE-2026-47380
was published
for
nocodb
(npm)
Jun 5, 2026
OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass...
Moderate
Unreviewed
CVE-2026-62220
was published
Jul 17, 2026
A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout...
High
Unreviewed
CVE-2026-14254
was published
Jul 16, 2026
PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access...
High
Unreviewed
CVE-2026-61458
was published
Jul 14, 2026
vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force...
Moderate
Unreviewed
CVE-2026-11915
was published
Jul 11, 2026
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable...
Moderate
Unreviewed
CVE-2026-15079
was published
Jul 11, 2026
Previously, there was no throttling on repeated authentication attempts
to the charging station...
High
Unreviewed
CVE-2026-42952
was published
Jul 11, 2026
9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
High
CVE-2026-55501
was published
for
9router
(npm)
Jul 6, 2026
MCO is vulnerable to Account Denial of Service due to improper implementation of password reset...
Moderate
Unreviewed
CVE-2026-53904
was published
Jul 1, 2026
KTM System e-BOK does not implement any limit or timeout on consecutive login attempts, allowing...
Moderate
Unreviewed
CVE-2026-35098
was published
Jun 30, 2026
Duplicate Advisory: Wildfly Elytron integration susceptible to brute force attacks via CLI
High
GHSA-3jxr-23ph-c89g
was published
for
org.wildfly.core:wildfly-elytron-integration
(Maven)
Mar 4, 2025
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API