GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
739 advisories
Filter by severity
Vikunja: OIDC email-fallback account linking ignores email_verified, enabling local-account takeover
High
CVE-2026-62367
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
pyLoad: Rate-Limit Bypass and Audit-Log Spoofing via Trusted Client-Controlled `X-Forwarded-For` Header
Moderate
GHSA-9q47-3cm2-2rp8
was published
for
pyload-ng
(pip)
Oct 9, 2026
Authentication Bypass by Spoofing vulnerability in WPMU DEV Forminator forminator allows Identity...
High
Unreviewed
CVE-2026-96336
was published
Oct 9, 2026
Authentication Bypass by Spoofing vulnerability in Liquid Web / StellarWP GiveWP give allows...
High
Unreviewed
CVE-2026-96333
was published
Oct 9, 2026
Malcolm's front nginx reverse proxy defines a "Dashboards → Arkime shortcut" location using a...
Moderate
Unreviewed
CVE-2026-107336
was published
Oct 8, 2026
Insufficient job validation for service accounts in Jacamar CI prior to v0.30.0 allows...
High
Unreviewed
CVE-2026-107589
was published
Oct 8, 2026
A vulnerability has been identified regarding insufficient validation in the Frappe Cloud/ERPNext...
Moderate
Unreviewed
CVE-2026-4894
was published
Oct 8, 2026
An authentication bypass and command injection vulnerability exists in the inter-switch remote...
High
Unreviewed
CVE-2026-87663
was published
Oct 8, 2026
An authorization logic vulnerability exists in the Brocade Fabric OS versions before 10.0.1 REST...
Moderate
Unreviewed
CVE-2026-87670
was published
Oct 8, 2026
An authentication and access control bypass vulnerability exists in the web server management...
Moderate
Unreviewed
CVE-2026-87686
was published
Oct 8, 2026
Payload authentication token field handling issue
Critical
CVE-2026-105863
was published
for
payload
(npm)
Oct 7, 2026
Authenticated users are able to manipulate both the SMTP
envelope “Envelope-from” and “From”...
Moderate
Unreviewed
CVE-2026-33586
was published
Oct 7, 2026
mppx-condition-gate: Free-access path grants on a self-declared wallet without proving control
High
CVE-2026-104891
was published
for
@insumermodel/mppx-condition-gate
(npm)
Oct 7, 2026
Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write
High
CVE-2026-105741
was published
for
langflow
(pip)
Oct 7, 2026
PraisonAI: AgentMail webhook lacks signature verification, allowing unauthenticated message injection and sender spoofing
High
CVE-2026-61428
was published
for
praisonai
(pip)
Oct 7, 2026
Apache YuniKorn 1.9.0 and earlier allows bypassing the check for the user annotation by setting a...
Moderate
Unreviewed
CVE-2026-97146
was published
Oct 7, 2026
An unauthenticated attacker located on an adjacent private network (or any attacker routed...
High
Unreviewed
CVE-2026-102161
was published
Oct 6, 2026
Unauthenticated Bypass Vulnerability in Login Lockdown <= 2.17 versions.
Moderate
Unreviewed
CVE-2026-97308
was published
Oct 6, 2026
Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions.
Moderate
Unreviewed
CVE-2026-39772
was published
Oct 6, 2026
Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions.
Moderate
Unreviewed
CVE-2026-105057
was published
Oct 6, 2026
Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.
High
Unreviewed
CVE-2026-41558
was published
Oct 6, 2026
proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
Critical
CVE-2026-90711
was published
for
proxy-addr
(npm)
Oct 5, 2026
Perforce P4 Search prior to 2026.4.2 trusts a client-supplied address when validating certain...
Moderate
Unreviewed
CVE-2026-103512
was published
Oct 5, 2026
ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login...
Critical
Unreviewed
CVE-2026-105215
was published
Oct 4, 2026
A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open...
High
Unreviewed
CVE-2026-104988
was published
Oct 2, 2026
ProTip!
Advisories are also available from the
GraphQL API