GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
30 advisories
Filter by severity
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
High
GHSA-h4hf-v6w5-897x
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change...
High
Unreviewed
CVE-2026-56305
was published
Jul 10, 2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions <...
High
Unreviewed
CVE-2026-54801
was published
Jul 9, 2026
OpenAM Account Takeover via Unverified Password Change in OAuth2 Module
High
CVE-2026-46623
was published
for
org.openidentityplatform.openam:openam-auth-oauth2
(Maven)
Jun 26, 2026
Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user...
High
Unreviewed
CVE-2025-71328
was published
Jun 26, 2026
Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change...
High
Unreviewed
CVE-2025-71337
was published
Jun 23, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
High
CVE-2026-42084
was published
for
openc3
(RubyGems)
Apr 22, 2026
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication...
High
Unreviewed
CVE-2026-27757
was published
Feb 27, 2026
EventSentry versions prior to 6.0.1.20 contain an unverified password change vulnerability in the...
High
Unreviewed
CVE-2026-24443
was published
Feb 24, 2026
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account...
High
Unreviewed
CVE-2026-24440
was published
Jan 26, 2026
A low-privileged user can bypass account credentials without confirming the user's current...
High
Unreviewed
CVE-2025-14751
was published
Jan 23, 2026
IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the...
High
Unreviewed
CVE-2025-13148
was published
Dec 11, 2025
Flowise does not Prevent Bypass of Password Confirmation - Unverified Password Change
High
GHSA-fjh6-8679-9pch
was published
for
flowise-ui
(npm)
Nov 14, 2025
Flowise doesn't Prevent Bypass of Password Confirmation through Unverified Email Change (credentials)
High
GHSA-x39m-3393-3qp4
was published
for
flowise-ui
(npm)
Nov 14, 2025
A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14...
High
Unreviewed
CVE-2025-61132
was published
Oct 23, 2025
Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality,...
High
Unreviewed
CVE-2025-22381
was published
Oct 16, 2025
FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the...
High
Unreviewed
CVE-2025-61536
was published
Oct 16, 2025
The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is...
High
Unreviewed
CVE-2025-5482
was published
Jun 4, 2025
The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege...
High
Unreviewed
CVE-2025-3607
was published
Apr 24, 2025
The Exertio Framework plugin for WordPress is vulnerable to privilege escalation via account...
High
Unreviewed
CVE-2024-13373
was published
Mar 1, 2025
The password change function at /cgi/admin.cgi does not require the current/old password, which...
High
Unreviewed
CVE-2024-28143
was published
Dec 12, 2024
An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote...
High
Unreviewed
CVE-2024-27715
was published
Jul 5, 2024
Mantis Bug Tracker (MantisBT) allows user account takeover in the signup/reset password process
High
CVE-2024-34077
was published
for
mantisbt/mantisbt
(Composer)
May 13, 2024
Expired tokens can be renewed without validating the account password
High
GHSA-9wgg-m99q-hhfc
was published
for
emailproxy
(pip)
Dec 19, 2023
The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up...
High
Unreviewed
CVE-2023-4214
was published
Nov 18, 2023
ProTip!
Advisories are also available from the
GraphQL API