GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
83 advisories
Filter by severity
Nexus Repository 3 contained an endpoint used to change the administrator account password during...
Moderate
Unreviewed
CVE-2026-17599
was published
Aug 7, 2026
The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via...
Critical
Unreviewed
CVE-2026-15964
was published
Aug 1, 2026
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
High
GHSA-h4hf-v6w5-897x
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows...
Critical
Unreviewed
CVE-2026-12692
was published
Jul 17, 2026
Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change...
High
Unreviewed
CVE-2026-56305
was published
Jul 10, 2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions <...
High
Unreviewed
CVE-2026-54801
was published
Jul 9, 2026
OpenAM Account Takeover via Unverified Password Change in OAuth2 Module
High
CVE-2026-46623
was published
for
org.openidentityplatform.openam:openam-auth-oauth2
(Maven)
Jun 26, 2026
Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user...
High
Unreviewed
CVE-2025-71328
was published
Jun 26, 2026
Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change...
High
Unreviewed
CVE-2025-71337
was published
Jun 23, 2026
The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password...
Critical
Unreviewed
CVE-2026-5386
was published
May 29, 2026
Unverified password change in Devolutions Server allows an attacker to change a user's password...
Low
Unreviewed
CVE-2026-9249
was published
May 26, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
High
CVE-2026-42084
was published
for
openc3
(RubyGems)
Apr 22, 2026
Navicat for Oracle 12.1.15 contains a denial of service vulnerability that allows local attackers...
Moderate
Unreviewed
CVE-2019-25653
was published
Mar 30, 2026
An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset...
Critical
Unreviewed
CVE-2026-30458
was published
Mar 26, 2026
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication...
High
Unreviewed
CVE-2026-27757
was published
Feb 27, 2026
EventSentry versions prior to 6.0.1.20 contain an unverified password change vulnerability in the...
High
Unreviewed
CVE-2026-24443
was published
Feb 24, 2026
A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects...
Moderate
Unreviewed
CVE-2026-2543
was published
Feb 16, 2026
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account...
High
Unreviewed
CVE-2026-24440
was published
Jan 26, 2026
A low-privileged user can bypass account credentials without confirming the user's current...
High
Unreviewed
CVE-2025-14751
was published
Jan 23, 2026
Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules...
Low
Unreviewed
CVE-2025-11235
was published
Jan 7, 2026
IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the...
High
Unreviewed
CVE-2025-13148
was published
Dec 11, 2025
Ibexa User Bundle is missing password change validation
Critical
CVE-2025-67719
was published
for
ibexa/user
(Composer)
Dec 10, 2025
An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7...
Moderate
Unreviewed
CVE-2025-59808
was published
Dec 9, 2025
Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2...
Critical
Unreviewed
CVE-2025-63362
was published
Dec 4, 2025
Flowise does not Prevent Bypass of Password Confirmation - Unverified Password Change
High
GHSA-fjh6-8679-9pch
was published
for
flowise-ui
(npm)
Nov 14, 2025
ProTip!
Advisories are also available from the
GraphQL API