GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,175
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
140 advisories
Filter by severity
The WebSocket Application Programming Interface lacks restrictions on the number of...
High
Unreviewed
CVE-2026-50176
was published
Jun 26, 2026
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user...
High
Unreviewed
CVE-2026-3329
was published
Jun 11, 2026
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft QR Menu...
High
Unreviewed
CVE-2025-2412
was published
Jun 6, 2026
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta...
High
Unreviewed
CVE-2025-2415
was published
Jun 6, 2026
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft OctoCloud...
High
Unreviewed
CVE-2025-2414
was published
Jun 6, 2026
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute...
High
Unreviewed
CVE-2026-36607
was published
Jun 3, 2026
In BYD Atto3, an attacker can obtain an authentication key through Brute Force attack, which is...
High
Unreviewed
CVE-2025-61081
was published
May 19, 2026
OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to...
High
Unreviewed
CVE-2023-54347
was published
May 5, 2026
U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the...
High
Unreviewed
CVE-2026-36959
was published
Apr 30, 2026
DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability,...
High
Unreviewed
CVE-2026-6947
was published
Apr 24, 2026
The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if...
High
Unreviewed
CVE-2025-14362
was published
Apr 21, 2026
The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if...
High
Unreviewed
CVE-2026-0972
was published
Apr 21, 2026
This vulnerability exists in Quantum Networks router due to missing rate limiting and CAPTCHA...
High
Unreviewed
CVE-2026-41037
was published
Apr 21, 2026
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting...
High
Unreviewed
CVE-2026-31851
was published
Mar 23, 2026
The WebSocket Application Programming Interface lacks restrictions on the number of...
High
Unreviewed
CVE-2026-31904
was published
Mar 21, 2026
The WebSocket Application Programming Interface lacks restrictions on the number of...
High
Unreviewed
CVE-2026-31903
was published
Mar 21, 2026
The WebSocket Application Programming Interface lacks restrictions on the number of...
High
Unreviewed
CVE-2026-24696
was published
Mar 6, 2026
The WebSocket Application Programming Interface lacks restrictions on the number of...
High
Unreviewed
CVE-2026-20882
was published
Mar 6, 2026
The WebSocket Application Programming Interface lacks restrictions on the number of...
High
Unreviewed
CVE-2026-27778
was published
Mar 6, 2026
The WebSocket Application Programming Interface lacks restrictions on
the number of...
High
Unreviewed
CVE-2026-24445
was published
Feb 27, 2026
The WebSocket Application Programming Interface lacks restrictions on
the number of...
High
Unreviewed
CVE-2026-26305
was published
Feb 27, 2026
The WebSocket Application Programming Interface lacks restrictions on
the number of...
High
Unreviewed
CVE-2026-25945
was published
Feb 27, 2026
The WebSocket Application Programming Interface lacks restrictions on
the number of...
High
Unreviewed
CVE-2026-25114
was published
Feb 27, 2026
The WebSocket Application Programming Interface lacks restrictions on
the number of...
High
Unreviewed
CVE-2026-25113
was published
Feb 27, 2026
The WebSocket Application Programming Interface lacks restrictions on
the number of...
High
Unreviewed
CVE-2026-20792
was published
Feb 27, 2026
ProTip!
Advisories are also available from the
GraphQL API